graphgrc

SCF - VPM-03 - Vulnerability Ranking

Mechanisms exist to identify and assign a risk ranking to newly discovered security vulnerabilities using reputable outside sources for security vulnerability information.

Mapped framework controls

ISO 27002

Control questions

Does the organization identify and assign a risk ranking to newly discovered security vulnerabilities using reputable outside sources for security vulnerability information?