A key factor in meeting NIS2 compliance with regard to a VDP is having clear vulnerability management. It is therefore important to have a defined process that takes over after a vulnerability report arrives. Without vulnerability management, the compliance is not valid.
When a vulnerability arrives through the VDP, it should go into a defined vulnerability-management process:
1. Receipt and confirmationThe vulnerability is received securely and it is assessed whether it is valid and relevant.
2. Risk assessment and prioritisationIt is assessed how serious the vulnerability is, which systems it affects and what impact it can have.
3. RemediationThe relevant team fixes the vulnerability or takes mitigating measures according to internal methodology.
4. Follow-up and closureIt is confirmed that the vulnerability is genuinely fixed and the case is closed with a record for traceability.
5. Communication (optional)Where applicable, the reporter is given confirmation or thanks for the report.
A VDP ensures that vulnerabilities arrive through the right channel, but vulnerability management ensures that they are responded to correctly, and it is important that all parties can absorb vulnerabilities reported through a VDP into their vulnerability-management process.
If any questions arise, please contact us here