Sheet SYN-02 — Network Operations Manual
Standards, Vulnerability & Health
Tenant-defined compliance policies, known-exploited vulnerability matching, and the composite health score that rolls it all up.
What this area covers
Once the inventory is trustworthy, the next question is whether the estate matches the standard the tenant has decided on, and how exposed it is. This area covers the compliance engine, vulnerability tracking, and the scoring layer that turns both into numbers leadership can act on.
Operational areas in scope
| Area | What operators need from it | Why it matters |
|---|---|---|
| Compliance policies | Tenant-defined rule sets scoped to an organization, a label, or a single site | The standard belongs to the tenant; nothing is hardcoded by Synapse |
| Wi-Fi standardization | A required SSID set per policy, with legacy detection and label-based exemptions | Wi-Fi drift is invisible until someone checks every site |
| Vulnerability tracking | Device matches against known exploited and published vulnerabilities, with severity rules | Known exploited vulnerabilities are the ones attackers are already using |
| Evaluation triggers | Results refresh after syncs, on a maintenance cycle, and on demand | A compliance answer is only useful if it reflects the current estate |
| Health scoring | Four dimensions folded into one weighted composite per site and rollup | One number invites action; four dimensions explain it |
| Honest absence | A dimension with no data shows as no data, never as zero | A missing measurement is not a failing one |
What operators are actually managing
- Define the standard as policy data: required SSIDs, severity thresholds, and exemptions.
- Pick the right scope for each policy: one organization, one site, or every site carrying a label.
- Review pass, fail, and not-applicable results with the structured evidence behind each one.
- Tune the scoring weights so the composite reflects what the business actually cares about.
- Use the refresh roadmap to plan hardware replacement before end-of-life becomes an incident.
What this public manual area includes
- Wi-Fi standardization policies and the compliance dashboard.
- Vulnerability management, including the known-exploited-vulnerabilities catalog view.
- Health scoring, trends, weights, and the refresh roadmap.
What healthy operation looks like
- Every site is either passing policy or has a failure someone owns.
- Exempted sites are exempt by explicit policy, not by being forgotten.
- Vulnerability matches on live devices get worked in severity order.
- Score trends move because the estate changed, and the evidence shows why.