FIRST CSIRT Services Framework and Standards
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST CSIRT Services Framework and Standards FIRST-PSIRT-Services: FIRST PSIRT Services Framework (2020) - Product Security Incident Response Team Service Catalog

FIRST PSIRT (Product Security Incident Response Team) Services Framework v1.1 published December 2020. SCOPE: parallel to CSIRT Services Framework but focused on PRODUCT VENDORS + PRODUCT TEAMS handling vulnerabilities + incidents affecting their products + customers + supply chains. SERVICE AREAS (6): (1) STAKEHOLDER MANAGEMENT - constituency + customer + researcher + supplier + regulator coordination; (2) VULNERABILITY DISCOVERY - intake from researchers + bug bounty + customer + supplier + internal sources; (3) VULNERABILITY TRIAGE + ANALYSIS - CVSS + CVE assignment + reproducibility + impact + scope; (4) REMEDIATION - patch development + workaround + customer communication + verification; (5) VULNERABILITY DISCLOSURE - advisory publication + customer notification + MPCVD coordination + supply-chain notification; (6) TRAINING + EDUCATION - internal product-team training + external researcher engagement + bug bounty program management + ISO/IEC 29147 + 30111 alignment. EU CRA + the 2024 OMB M-22-09 + the FedRAMP M-24-15 modernization all emphasise PSIRT capability for federal-adjacent + EU-marketed products + cloud services.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.