ISO/IEC 30111:2019
Clause 7: Vulnerability handling process – ISO/IEC 30111:2019

ISO/IEC 30111:2019 7.1.6: 7.1.6 Release

There are two routes by which a vendor can remediate, usually one and occasionally both. For a vulnerability in a service, it follows its own processes for deploying updates or changing configuration on production systems. For a vulnerability in a product, once it is confident the remediation works, it releases it through the processes ISO/IEC 29147 sets out. Where users must also do something (change passwords, sign out and back in), the vendor tells them in a security advisory under ISO/IEC 29147, and where an outside party made the report, ISO/IEC 29147 governs how the vendor deals with external interested parties.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • Annex I Part II(8) Dissemination of security updates without delay and free of charge, with advisories

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Clause 7: Vulnerability handling process – ISO/IEC 30111:2019

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.