Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers)
|
|
| stereotype | ControlObjective |
| namespace | NIST_CSF |
| status | MANDATORY |
| refCode | RS.AN-5 |
| cis_crc | 4, 19 |
| cobit | EDM03.02, DSS05.07 |
| nist-sp800-53 | SI-5, PM-15 |