Prompt Issuance of CVE Notices for Critical Vulnerabilities, v1.0
Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to issue common vulnerability and exposure (CVE) notices promptly for all critical/high-impact vulnerabilities requiring customer action or under active exploitation, for all of its product and service offerings.
Assessment Step
1
Prompt Issuance of CVE Notices for Critical Vulnerabilities (PromptIssuanceofCVENoticesforCriticalVulnerabilities)
For all of its product and service offerings, does the organization issue common vulnerability and exposure (CVE) notices promptly for all critical/high-impact vulnerabilities requiring customer action or under active exploitation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Prompt Issuance of CVE Notices for Critical Vulnerabilities
For all of its product and service offerings, the organization must issue common vulnerability and exposure (CVE) notices promptly for all critical/high-impact vulnerabilities requiring customer action or under active exploitation.
Citation
SBDP
(doc)
|