International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 29147:2020 and nationally

ISO/IEC 29147:2018

110 controls. 302 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

110 controls 302 frameworks share controls with it International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 29147:2020 and nationally verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
29147-5.1Vulnerability Disclosure Policy0
29147-5.10Disclosure Records and Retention0
29147-5.11Researcher Safe Harbour and Legal Posture159
29147-5.12Bug Bounty Programme Integration0
29147-5.13External Stakeholder Notification0
29147-5.14Embargo Management0
29147-5.15Programme Governance and Roles0
29147-5.16Training and Awareness1
29147-5.2Receipt of Vulnerability Reports0
29147-5.3Initial Triage and Verification0
29147-5.4Finder Communication and Coordination0
29147-5.5Coordinated Disclosure Timeline0
29147-5.6Advisory Content and Quality64
29147-5.7Multi-Party Coordination0
29147-5.8Confidentiality of Reports18
29147-5.9Post-Disclosure Monitoring0
29147-6.1General receiving guidelines0
29147-6.2Vulnerability report contents0
29147-6.3Initial assessment0
29147-6.4Further investigation0
29147-6.5Ongoing communication0
29147-6.6Coordinator involvement0
29147-6.7Operational security0
29147-7.3Advisory publication guidelines0
29147-7.4Advisory content elements0
29147-7.5Communication channels13
29147-7.6Advisory format0
29147-7.7Advisory authenticity0
29147-7.8Remediation information64
29147-8.1Coordination general0
29147-8.2Vendors playing multiple roles0
29147-9.1Vulnerability disclosure policy development0
29147-9.2Contact mechanisms and scope169
29147-9.3Communication expectations and timelines13
55 Concepts0
5.105.10 Vulnerability exploitation0
5.115.11 Vulnerabilities and risk0
5.35.3 Relationships to other International Standards0
5.3.15.3.1 ISO/IEC 301110
5.45.4 Systems, components, and services0
5.4.65.4.6 Product interdependency0
5.55.5 Stakeholder roles0
5.5.25.5.2 User0
5.5.35.5.3 Vendor0
5.5.45.5.4 Reporter0
5.5.55.5.5 Coordinator0
5.65.6 Vulnerability handling process summary0
5.6.85.6.8 Embargo period0
5.75.7 Information exchange during vulnerability disclosure0
5.85.8 Confidentiality of exchanged information0
5.8.25.8.2 Secure communications0
5.95.9 Vulnerability advisories0
66 Receiving vulnerability reports0
6.26.2 Vulnerability reports0
6.2.26.2.2 Capability to receive reports0
6.2.36.2.3 Monitoring0
6.2.46.2.4 Report tracking0
6.2.56.2.5 Report acknowledgement0
6.36.3 Initial assessment0
6.46.4 Further investigation0
6.56.5 On-going communication0
6.66.6 Coordinator involvement0
6.76.7 Operational security0
77 Publishing vulnerability advisories0
7.27.2 Advisory0
7.37.3 Advisory publication timing0
7.47.4 Advisory elements0
7.4.107.4.10 Impact0
7.4.117.4.11 Severity0
7.4.127.4.12 Remediation0
7.4.137.4.13 References0
7.4.147.4.14 Credit0
7.4.157.4.15 Contact information0
7.4.167.4.16 Revision history0
7.4.177.4.17 Terms of use0
7.4.27.4.2 Identifiers0
7.4.37.4.3 Date and time0
7.4.47.4.4 Title0
7.4.57.4.5 Overview0
7.4.67.4.6 Affected products0
7.4.77.4.7 Intended audience0
7.4.87.4.8 Localization0
7.4.97.4.9 Description0
7.57.5 Advisory communication0
7.67.6 Advisory format0
7.77.7 Advisory authenticity0
7.87.8 Remediations0
7.8.27.8.2 Remediation authenticity0
7.8.37.8.3 Remediation deployment0
88 Coordination0
8.18.1 Coordination: general0
8.28.2 Vendors playing multiple roles0
8.2.28.2.2 Vulnerability reporting among vendors0
8.2.38.2.3 Reporting vulnerability information to other vendors0
99 Vulnerability disclosure policy0
9.29.2 Required policy elements0
9.2.29.2.2 Preferred contact mechanism0
9.39.3 Recommended policy elements0
9.3.29.3.2 Vulnerability report contents0
9.3.39.3.3 Secure communication options0
9.3.49.3.4 Setting communication expectations0
9.3.59.3.5 Scope0
9.3.69.3.6 Publication0
9.3.79.3.7 Recognition0
9.49.4 Optional policy elements0
9.4.29.4.2 Legal considerations0
9.4.39.4.3 Disclosure timeline0
ANNEXESAnnexes A to D (informative)0
STANDARDISO/IEC 29147:2018: the standard, its scope and what is held0
STATUSEdition status: the 2018 second edition is current; the CRA and EUCC point at it0

Tell me when ISO/IEC 29147:2018 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 29147:2018, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition