FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency. SUB-SERVICES: (1) VULNERABILITY DISCOVERY - active scanning + bug bounty + research + threat intel + supplier notifications; (2) VULNERABILITY REPORT INTAKE - structured intake from researchers + vendors + government via secure channels; (3) VULNERABILITY ANALYSIS - CVSS scoring (Base + Threat + Environmental + Supplemental in CVSS v4 or Base + Temporal + Environmental in CVSS v3.1) + exploitability + scope + privilege + UI metrics + assignment of CVE; (4) VULNERABILITY COORDINATION - multi-party coordinated disclosure per MPCVD Guidelines + ISO/IEC 29147 + ISO/IEC 30111; (5) VULNERABILITY DISCLOSURE - publication of advisory with mitigation + workarounds + technical details + IOCs + TLP classification; (6) VULNERABILITY RESPONSE - patch rollout assistance + risk-based prioritization + CISA KEV alignment + EU CRA vulnerability handling obligations + the 2024 OMB M-22-09 phishing-resistant remediation timelines.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.