- Job title
- Product Manager
- Sector
- Catering
- Organization type
- 20-person company
- Joined
- Feb 2024
- Message
- 220
Doki · Corporate website · 2024
We are a 14-person team developing custom software for public enterprises and municipal entities in Germany. In a recently signed framework agreement, the primary client stipulated that the infrastructure we deliver must implement vulnerability management (Schwachstellenmanagement) compliant with standards set by the Federal Office for Information Security (BSI).
Until now, our system administrator applied weekly updates manually, and whenever a critical security advisory surfaced, we remediated it the same day. However, the client is demanding an auditable, documented process with regular reporting. We have allocated a budget of around 8,000 EUR and a 2-month ramp-up window for this effort.
Without going through a full-scale institutional BSI certification from scratch, what exactly must a baseline vulnerability management lifecycle cover to pass the client's audit? From inventory to patch scheduling and log retention, what concrete steps do we need to take?