TVM-09: Is a process defined and implemented to track and report vulnerability identification
and remediation activities that include stakeholder notification?
The integrated TVM system should have comprehensive vulnerability tracking capabilities. Capabilities should include when discoveries were made and remediated, systems impacted, reasons for the delay (where applicable), and any communications that may have been made to stakeholders.
Control implemented
Control ownership
Description
Define and implement a process for tracking and reporting vulnerability
identification and remediation activities that includes stakeholder notification.