Publication of CVE Root Cause Analyses, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to publish root-cause analyses of common vulnerabilities and exposures (CVEs), across all of its product and service offerings.

Assessment Step

1
Publication of CVE Root Cause Analyses (PublicationofCVERootCauseAnalyses)
Across all of its product and service offerings, does the organization publish root-cause analyses of common vulnerabilities and exposures (CVEs)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Publication of CVE Root Cause Analyses
Across all of its product and service offerings, the organization must publish root-cause analyses of common vulnerabilities and exposures (CVEs).
Citation
SBDP
(doc)