30111-5.1 | Organizational policy | 169 |
30111-5.2 | Vulnerability handling team | 142 |
30111-5.3 | Roles and responsibilities | 2 |
30111-5.4 | Integration with disclosure process | 0 |
30111-6.1 | Vulnerability Handling Policy | 0 |
30111-6.10 | Tracking and Status Reporting | 0 |
30111-6.11 | Coordination with Disclosure Process | 0 |
30111-6.12 | Root Cause Analysis | 0 |
30111-6.13 | Metrics and Programme Performance | 0 |
30111-6.14 | Records Retention and Auditability | 0 |
30111-6.15 | Roles, Responsibilities, and Resourcing | 0 |
30111-6.16 | Training for Handling Personnel | 0 |
30111-6.17 | Customer Notification and Support | 0 |
30111-6.2 | Vulnerability Receipt and Initial Assessment | 0 |
30111-6.3 | Verification and Reproduction | 1 |
30111-6.4 | Severity and Impact Analysis | 0 |
30111-6.5 | Remediation Strategy Selection | 17 |
30111-6.6 | Patch Development and Code Review | 0 |
30111-6.7 | Fix Verification Testing | 0 |
30111-6.8 | Release Management and Distribution | 0 |
30111-6.9 | Supplier and Component Coordination | 0 |
30111-7.1 | Tracking and prioritization | 0 |
30111-7.2 | Communication management | 13 |
30111-7.3 | Quality assurance of remediation | 17 |
30111-7.4 | Process documentation and improvement | 0 |
30111-8.1 | Post-release monitoring | 64 |
30111-8.2 | Lessons learned | 0 |
30111-8.3 | Root cause analysis | 0 |
5 | 5 Relationships to other International Standards | 0 |
5.1 | 5.1 ISO/IEC 29147 | 0 |
6 | 6 Policy and organizational framework | 0 |
6.1 | 6.1 Policy and organizational framework: general | 0 |
6.2 | 6.2 Leadership | 0 |
6.2.1 | 6.2.1 Leadership and commitment | 0 |
6.2.2 | 6.2.2 Policy | 0 |
6.2.3 | 6.2.3 Organizational roles, responsibilities and authorities | 0 |
6.3 | 6.3 Vulnerability handling policy development | 0 |
6.4 | 6.4 Organizational framework development | 0 |
6.5 | 6.5 Vendor CSIRT or PSIRT | 0 |
6.5.2 | 6.5.2 PSIRT mission | 0 |
6.5.3 | 6.5.3 PSIRT responsibilities | 0 |
6.5.3.2 | 6.5.3.2 Public vulnerability monitoring | 0 |
6.5.3.3 | 6.5.3.3 Communication with external reporters | 0 |
6.5.3.4 | 6.5.3.4 Communication within the vendor organization | 0 |
6.5.3.5 | 6.5.3.5 Communication with coordinators or other vendors | 0 |
6.5.3.6 | 6.5.3.6 Timing of public vulnerability disclosure | 0 |
6.5.3.7 | 6.5.3.7 Internal vulnerability assessment | 0 |
6.5.3.8 | 6.5.3.8 Inventory and supply chain tracking | 0 |
6.5.4 | 6.5.4 Staff capabilities | 0 |
6.6 | 6.6 Responsibilities of the product business division | 0 |
6.7 | 6.7 Responsibilities of customer support and public relations | 0 |
6.8 | 6.8 Legal consultation | 0 |
7 | 7 Vulnerability handling process | 0 |
7.1 | 7.1 Vulnerability handling phases | 0 |
7.1.2 | 7.1.2 Preparation | 0 |
7.1.3 | 7.1.3 Receipt | 0 |
7.1.4 | 7.1.4 Verification | 0 |
7.1.5 | 7.1.5 Remediation development | 0 |
7.1.6 | 7.1.6 Release | 0 |
7.1.7 | 7.1.7 Post-release | 0 |
7.2 | 7.2 Process monitoring | 0 |
7.3 | 7.3 Confidentiality of vulnerability information | 0 |
8 | 8 Supply chain considerations | 0 |
RELATED | 5.2 to 5.4: the related standards the document draws on | 0 |
STANDARD | ISO/IEC 30111:2019: the standard, its scope and what is held | 0 |
STATUS | Edition status: the 2019 second edition is current; the CRA makes the process a legal obligation for EU products with digital elements | 0 |