A service level should create predictable action, not an artificial compliance cliff. Strong programmes use evidence-led response targets and a controlled exception path.
Define the clock precisely
State whether time starts at publication, detection, validation or assignment. Detection-to-validation is often the most controllable operational measure, while known exploitation may require an immediate response path.
Use priority bands with overrides
A small number of response bands is easier to govern. Confirmed exploitation, internet exposure or a critical attack path should be able to shorten the target regardless of CVSS.
Stop the clock only with evidence
Closure means the vulnerable version or usable attack path is gone. A ticket marked complete without a rescan, configuration check or equivalent proof is not closure.
Practical next steps
- Publish clock start, pause and closure rules.
- Create an emergency route for known exploitation.
- Require risk-owner approval for exceptions.
- Report age distribution and validated closure, not only pass rate.