ISO/IEC 29147:2018
Clause 6: Receiving vulnerability reports – ISO/IEC 29147:2018

ISO/IEC 29147:2018 6.2.2: 6.2.2 Capability to receive reports

A vendor should set up, and make public, a way for outside parties to send it vulnerability reports, usually one dedicated email address or web form acting as the single point of entry, easy to locate and named in the disclosure policy. The UK PSTI regulations make publishing how to reach this mechanism, in English, free of charge, without prior request and without asking for personal data, part of a deemed-compliance route for consumer connectable products; the CRA harmonized-standard draft treats the clause as its capability-to-receive-reports requirement, and ISO/IEC 30111 6.5.3.3 gives the PSIRT the job of building that entry point.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • Annex I Part II(6) Facilitating vulnerability information sharing, with a contact address
  • Annex II 2 User information: vulnerability contact point and CVD policy location

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 6: Receiving vulnerability reports – ISO/IEC 29147:2018

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.