Vulnerability remediation
A critical vulnerability is discovered in an internet-facing service.
The SLA is 30 days.
The team fixes it in three days because they understand the exposure.
There is no audit requirement forcing the earlier action.
The standard matters even when the deadline allows more time.