Establish and maintain a severity rating system and process for application vulnerabilities that
facilitates prioritizing the order in which discovered vulnerabilities are fixed. This process includes
setting a minimum level of security acceptability for releasing code or applications. Severity ratings
bring a systematic way of triaging vulnerabilities that improves risk management and helps ensure
the most severe bugs are fixed first. Review and update the system and process annually.
The organization has defined a process for addressing identified technical vulnerabilities.
Some vulnerabilities can be fixed directly, but vulnerabilities that have a significant impact should also be documented as security incidents. Once a vulnerability with significant impacts has been identified:
The organization develops a detailed severity rating system for vulnerabilities, defining criteria for severity levels, integrating these ratings into development workflows, setting security standards, using automated assessment tools, establishing a triage process, and reviewing the system annually to ensure effective vulnerability management.