ISO/IEC 30111:2019
Information technology — Security techniques — Vulnerability handling processes
Information technology — Security techniques — Vulnerability handling processes
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 13
- Дата публикации:
- 1 октября 2019 г.
- Издание:
- ISO/IEC IS 30111 edition 2 version 1
- ICS:
- 35.030
This document provides requirements and recommendations for how to process and remediate reported potential vulnerabilities in a product or service. This document is applicable to vendors involved in handling vulnerabilities.
Abstract
Overview
ISO/IEC 30111:2019 - Information technology - Security techniques - Vulnerability handling processes - defines requirements and recommendations for how vendors should process, investigate and remediate reported potential vulnerabilities in products and services. Intended for vendors, developers, evaluators and users, the standard prescribes a documented, repeatable vulnerability handling process and organizational framework to ensure timely, secure and accountable remediation.
Key topics and requirements
- Vulnerability handling lifecycle: Defines phases vendors should implement, including preparation, receipt, verification, remediation development, release, and post-release monitoring and follow-up.
- Policy and leadership: Requires top-management commitment, a documented internal vulnerability handling policy, objectives aligned with organizational strategy, and assignment of roles, responsibilities and authorities.
- Organizational structure: Recommends establishing or coordinating a PSIRT (Product Security Incident Response Team) or CSIRT capability, defining mission, responsibilities and staff capabilities.
- Confidentiality and disclosure controls: Emphasizes safeguards to prevent premature disclosure of vulnerability information and coordination with external disclosure policies.
- Process monitoring and improvement: Calls for periodic assessment, performance reporting to management, and continual improvement of the vulnerability handling process.
- Supply chain considerations: Addresses the need to consider ICT supply chain security when investigating and remediating vulnerabilities.
- Documentation and traceability: Vendors should document procedures and methods to track all reported vulnerabilities and remediation actions.
Practical applications & who uses it
- Software and hardware vendors use ISO/IEC 30111:2019 to build or improve their vulnerability handling processes (PSIRT/CSIRT), ensuring consistent triage, root-cause analysis and remediation workflows.
- Security teams and developers follow the standard to integrate vulnerability remediation with secure development lifecycles and application security practices.
- Evaluators and auditors use the standard to assess a vendor’s vulnerability handling maturity and conformance.
- Procurement and security-conscious buyers reference its requirements to set vendor expectations and contract clauses for product security and disclosure practices.
- Legal, customer support and PR teams leverage the recommended organizational roles to coordinate communications and legal risk management during vulnerability incidents.
Related standards
- ISO/IEC 29147 (Vulnerability disclosure) - meant to be used in conjunction with ISO/IEC 30111 for external reporting and remediation information distribution.
- ISO/IEC 27034 (Application security) and ISO/IEC 27036‑3 (ICT supply chain security) - provide complementary guidance on secure development and supply chain considerations.
- ISO/IEC 15408-3 - referenced for relevant assurance considerations.
Keywords: ISO/IEC 30111:2019, vulnerability handling, vulnerability disclosure, PSIRT, CSIRT, remediation process, security techniques, vendor vulnerability policy, supply chain security.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 30111:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 29147:2018
ДействующийInformation technology — Security techniques — Vulnerability disclosure
Overview ISO/IEC 29147:2018 - Information technology - Security techniques - Vulnerability disclosure - provides requirements and recommendations to vendors for responsibly receiving, handling and pu…
BS EN ISO/IEC 30111:2020
ДействующийInformation technology. Security techniques. Vulnerability handling processes.
BS ISO/IEC 27034-3:2018
ДействующийInformation technology. Application security. Application security management process.
ISO/IEC 27036-3:2023
ДействующийCybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain…
Overview ISO/IEC 27036-3:2023 - "Cybersecurity - Supplier relationships - Part 3" provides practical guidance for acquirers and suppliers of hardware, software, and services to manage information sec…