18.8: Establish a Process to Accept and Address Reports of Software Vulnerabilities

CSF v1.1 References:

Threats Addressed:


Control Statement

Establish a process to accept and address reports of software vulnerabilities, including providing a means for external entities to contact your security group.

