BS EN ISO/IEC 30111:2020
$102.76
Information technology. Security techniques. Vulnerability handling processes
Published By | Publication Date | Number of Pages |
BSI | 2020 | 22 |
This document provides requirements and recommendations for how to process and remediate reported potential vulnerabilities in a product or service.
This document is applicable to vendors involved in handling vulnerabilities.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
4 | European foreword Endorsement notice |
6 | Foreword |
7 | Introduction |
9 | 1 Scope 2 Normative references 3 Terms and definitions 4 Abbreviated terms 5 Relationships to other International Standards 5.1 ISO/IEC 29147 |
10 | 5.2 ISO/IEC 27034 (all parts) 5.3 ISO/IEC 27036-3 |
11 | 5.4 ISO/IEC 15408-3 6 Policy and organizational framework 6.1 General 6.2 Leadership 6.2.1 Leadership and commitment 6.2.2 Policy |
12 | 6.2.3 Organizational roles, responsibilities, and authorities 6.3 Vulnerability handling policy development 6.4 Organizational framework development |
13 | 6.5 Vendor CSIRT or PSIRT 6.5.1 General 6.5.2 PSIRT mission 6.5.3 PSIRT responsibilities |
14 | 6.5.4 Staff capabilities 6.6 Responsibilities of the product business division |
15 | 6.7 Responsibilities of customer support and public relations 6.8 Legal consultation 7 Vulnerability handling process 7.1 Vulnerability handling phases 7.1.1 General |
16 | 7.1.2 Preparation 7.1.3 Receipt |
17 | 7.1.4 Verification |
18 | 7.1.5 Remediation development 7.1.6 Release 7.1.7 Post-release |
19 | 7.2 Process monitoring 7.3 Confidentiality of vulnerability information 8 Supply chain considerations |
21 | Bibliography |