ISO/IEC 29147:2018
Clause 6: Receiving vulnerability reports – ISO/IEC 29147:2018

ISO/IEC 29147:2018 6.3: 6.3 Initial assessment

The vendor should make an initial assessment of each report to decide whether it describes a potential vulnerability in a supported product or service and how urgent it is, the first step of the verification ISO/IEC 30111 7.1.4 a) and e) describes (initial investigation and prioritization), and tell the reporter the outcome.

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 6: Receiving vulnerability reports – ISO/IEC 29147:2018

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.