ISO/IEC 30111:2019
Clause 7: Vulnerability handling process – ISO/IEC 30111:2019

ISO/IEC 30111:2019 7.1.2: 7.1.2 Preparation

Before launching a programme for handling vulnerabilities, vendors should put in place the policy (6.3), the processes and the capability. They may set up a response team (PSIRT or CSIRT) and internal security assessment teams, recruit and assign people, and build tools. Vendors shall put in place a process for disclosing vulnerabilities as ISO/IEC 29147 defines it.

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 7: Vulnerability handling process – ISO/IEC 30111:2019

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.