International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 30111:2020 and nationally (DIN EN ISO/IEC 30111:2020 held)

ISO/IEC 30111:2019

66 controls. 275 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

66 controls 275 frameworks share controls with it International (ISO/IEC JTC 1/SC 27); adopted as EN ISO/IEC 30111:2020 and nationally (DIN EN ISO/IEC 30111:2020 held) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
30111-5.1Organizational policy169
30111-5.2Vulnerability handling team142
30111-5.3Roles and responsibilities2
30111-5.4Integration with disclosure process0
30111-6.1Vulnerability Handling Policy0
30111-6.10Tracking and Status Reporting0
30111-6.11Coordination with Disclosure Process0
30111-6.12Root Cause Analysis0
30111-6.13Metrics and Programme Performance0
30111-6.14Records Retention and Auditability0
30111-6.15Roles, Responsibilities, and Resourcing0
30111-6.16Training for Handling Personnel0
30111-6.17Customer Notification and Support0
30111-6.2Vulnerability Receipt and Initial Assessment0
30111-6.3Verification and Reproduction1
30111-6.4Severity and Impact Analysis0
30111-6.5Remediation Strategy Selection17
30111-6.6Patch Development and Code Review0
30111-6.7Fix Verification Testing0
30111-6.8Release Management and Distribution0
30111-6.9Supplier and Component Coordination0
30111-7.1Tracking and prioritization0
30111-7.2Communication management13
30111-7.3Quality assurance of remediation17
30111-7.4Process documentation and improvement0
30111-8.1Post-release monitoring64
30111-8.2Lessons learned0
30111-8.3Root cause analysis0
55 Relationships to other International Standards0
5.15.1 ISO/IEC 291470
66 Policy and organizational framework0
6.16.1 Policy and organizational framework: general0
6.26.2 Leadership0
6.2.16.2.1 Leadership and commitment0
6.2.26.2.2 Policy0
6.2.36.2.3 Organizational roles, responsibilities and authorities0
6.36.3 Vulnerability handling policy development0
6.46.4 Organizational framework development0
6.56.5 Vendor CSIRT or PSIRT0
6.5.26.5.2 PSIRT mission0
6.5.36.5.3 PSIRT responsibilities0
6.5.3.26.5.3.2 Public vulnerability monitoring0
6.5.3.36.5.3.3 Communication with external reporters0
6.5.3.46.5.3.4 Communication within the vendor organization0
6.5.3.56.5.3.5 Communication with coordinators or other vendors0
6.5.3.66.5.3.6 Timing of public vulnerability disclosure0
6.5.3.76.5.3.7 Internal vulnerability assessment0
6.5.3.86.5.3.8 Inventory and supply chain tracking0
6.5.46.5.4 Staff capabilities0
6.66.6 Responsibilities of the product business division0
6.76.7 Responsibilities of customer support and public relations0
6.86.8 Legal consultation0
77 Vulnerability handling process0
7.17.1 Vulnerability handling phases0
7.1.27.1.2 Preparation0
7.1.37.1.3 Receipt0
7.1.47.1.4 Verification0
7.1.57.1.5 Remediation development0
7.1.67.1.6 Release0
7.1.77.1.7 Post-release0
7.27.2 Process monitoring0
7.37.3 Confidentiality of vulnerability information0
88 Supply chain considerations0
RELATED5.2 to 5.4: the related standards the document draws on0
STANDARDISO/IEC 30111:2019: the standard, its scope and what is held0
STATUSEdition status: the 2019 second edition is current; the CRA makes the process a legal obligation for EU products with digital elements0

Tell me when ISO/IEC 30111:2019 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 30111:2019, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition