16 Jan 2024 02:32 PM
Hello,
Does Dynatrace publish vulnerability remediation SLAs or make information publicly available on how soon they make fixes available when a vulnerability is discovered? Specifically I am looking for information on SLAs for critical severity CVEs. Thanks.
Solved! Go to Solution.
16 Jan 2024 02:52 PM
Hey @pny10x64 i found something on Dynatrace Blog
Severity is very important as it not only defines impact but also defines the priority and “Time until Fix is in Production”. You could also explain it as our internal Service Level Agreement (SLA) until the problem is remediated for the customer. The following shows the full remediation timeline table explaining every severity level including our SLA to remediate the problem
In this Link you can see all the information that you want about SLA vulnerabilities in Dynatrace
16 Jan 2024 03:02 PM
Hi,
we have not publicly published our vulnerability remediation SLAs. Critical severity vulnerabilities (CVEs or vulnerabilities in our own code) are required to be remediated within 72 hours.