PR.IP-12.1: The organization shall establish and maintain a documented process that allows continuous review of vulnerabilities and strategies to mitigate them.
Consider inventorying sources likely to report vulnerabilities in the identified components and distribute updates (software publisher websites, CERT website, ENISA website).
The organization should identify where its critical system's vulnerabilities may be exposed to adversaries.
Documentation Maturity
Implementation Maturity
Description
The organization shall establish and maintain a documented process that allows continuous review of vulnerabilities and strategies to mitigate them.