OPS-18—Managing Vulnerabilities, Malfunctions and Errors - Concept
>Control Description
Guidelines and instructions with technical and organisational measures are documented, communicated and provided in accordance with SP-01 to ensure the timely identification and addressing of vulnerabilities in the system components used to provide the cloud service. These guidelines and instructions contain specifications regarding the following aspects:
• Regular identification of vulnerabilities;
• Assessment of the severity of identified vulnerabilities;
• Prioritisation and implementation of actions to promptly remediate or mitigate identified vulnerabilities based on severity and according to defined timelines; and
• Handling of system components for which no measures are initiated for the timely remediation or mitigation of vulnerabilities.
Additional criteria: -
Ask AI
Configure your API key to use AI features.