ISO/IEC 27000 Management of Technical Vulnerabilities, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to management of technical vulnerabilities.
Assessment Step
1
Management of Technical Vulnerabilities (ManagementofTechnicalVulnerabilities)
Is information about technical vulnerabilities of information systems in use obtained, the organization's exposure to such vulnerabilities evaluated, and appropriate measures taken?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Management of Technical Vulnerabilities
Information about technical vulnerabilities of information systems in use shall be obtained, the organization's exposure to such vulnerabilities shall be evaluated and appropriate measures shall be taken.
Citations
27001
Annex A, Control 8.8
27002
Section 8.8
|