Vulnerability Management & Testing

Vulnerability management, testing, and remediation processes at FMIS

FMIS Vulnerability Management

Vulnerability Management & Testing

FMIS applies a structured approach to identifying, assessing, and resolving security vulnerabilities across both development and hosted environments. This combines ongoing monitoring, automated scanning, and independent testing.

Security and compliance enquiries
Security & compliance

If you have questions about security, data protection, or require documentation for a review, get in touch with our team.

Email our team Privacy policy Cookie policy
General enquiries: +44 (0) 1227 773003 Mon–Fri, 9:00–17:00 (BST/GMT)

FMIS Vulnerability Management Approach

Approach

Vulnerability management is integrated into both system development and day-to-day operations.

  • Code is reviewed and scanned during development
  • Systems are monitored and assessed in production environments
  • Findings are logged, prioritised, and resolved through defined processes

This ensures that potential risks are identified early and managed consistently.

FMIS Code Scanning

Code and system scanning

FMIS uses a combination of code-level and system-level scanning to detect vulnerabilities.

  • Code scanning identifies issues during development
  • System scanning validates the security of hosted environments
  • Findings are reviewed and addressed as part of controlled processes

Recent system-level scanning has confirmed that hosted environments are securely configured, with no outstanding critical issues following remediation.

FMIS Independent Code Testing and Penetration Testing

Independent testing

FMIS carries out regular independent testing to validate its security posture.

This includes annual infrastructure and application penetration testing (ITHC). Findings are reviewed and addressed through defined remediation processes.

This provides an external assessment of system security in addition to internal controls.

FMIS Bug Tracking and Remediation

Remediation and tracking

All identified vulnerabilities are managed through a structured process.

  • Issues are logged and assessed based on severity
  • Remediation actions are defined and implemented
  • Updates are tested and verified before release

This ensures that vulnerabilities are addressed in a controlled and traceable way.

FMIS Continuous Improvement

Continuous review

Vulnerability management is reviewed as part of the wider ISMS.

  • Results are reviewed during internal audits and management reviews
  • Processes are updated based on findings and evolving risks
  • Security controls are refined over time

This supports ongoing improvement rather than one-off remediation.

Further information

If you require additional detail on vulnerability management or testing processes, please contact:

privacy@fmis.co.uk

G-Cloud 15 - Government Commercial Agency Supplier logo

FMIS awarded G-Cloud 15 supplier status

FMIS Asset Management Software awarded G-Cloud 15 Supplier Status for Fixed Asset Management, Lease Accounting, Asset Tracking & Equipment Maintenance software.
UK public-sector indexation

Indexation in UK Public Sector Fixed Asset Accounting

Understanding how indexation fits alongside revaluation is now essential for finance teams managing non-current assets in the public sector.
Non-Current Assets vs Fixed Assets In the UK public-sector

Why the UK Public Sector Is Moving from Fixed Assets to Non Current Assets

Why is the UK public sector shifting to non-current assets, and how does FMIS software enhance control and compliance?
SORP_Lease_Accounting_changes_2026