graphgrc

SCF - IRO-10.3 - Vulnerabilities Related To Incidents

Mechanisms exist to report system vulnerabilities associated with reported cybersecurity & data privacy incidents to organization-defined personnel or roles.

Mapped framework controls

ISO 27002

Control questions

Does the organization report system vulnerabilities associated with reported cybersecurity & data privacy incidents to organization-defined personnel or roles?