Establish and maintain a process to accept and address reports of software vulnerabilities,
including providing a means for external entities to report. The process is to include such items
as: a vulnerability handling policy that identifies reporting process, responsible party for handling
vulnerability reports, and a process for intake, assignment, remediation, and remediation testing. As
part of the process, use a vulnerability tracking system that includes severity ratings and metrics
for measuring timing for identification, analysis, and remediation of vulnerabilities. Review and
update documentation annually, or when significant enterprise changes occur that could impact
this Safeguard.
Third-party application developers need to consider this an externally-facing policy that helps to set
expectations for outside stakeholders.
The organization has defined a process for addressing identified technical vulnerabilities.
Some vulnerabilities can be fixed directly, but vulnerabilities that have a significant impact should also be documented as security incidents. Once a vulnerability with significant impacts has been identified:
The organization needs to define Monitored Metrics for identifying and correcting vulnerabilities. Meters must be monitored at specified intervals.