Skip to content

Hide Navigation Hide TOC

Function: Vulnerability remediation development (3282999a-09d1-5d99-9d23-4773611775be)

This function will ideally identify a remediation or a fix for a vulnerability. If a vendor patch or fix is not available in a timely manner, a temporary solution or workaround, called a mitigation, may be recommended, such as disabling the affected software or making configuration changes, to minimize the potential negative effects of the vulnerability. Note that the actual application or deployment of a remediation (patch) or mitigation (workaround) is a function of a separate service, called Vulnerability Response in this framework. As part of the Vulnerability Analysis service and Remediation Development, this function may optionally include other sub-functions or activities, such as validating the changing of a procedure or design, reviewing remediation by a third party, or identifying any new vulnerabilities introduced in the remediation steps. Vulnerabilities that are not remediated or mitigated should be documented as acceptable risks. This function will often receive information or input from the affected product’s vendor(s), sometimes as part of the initial report or announcement handled by other services or functions.

Cluster A Galaxy A Cluster B Galaxy B Level
Service: Vulnerability analysis (e428df3a-7353-5854-b967-fbbb47079ff6) FIRST CSIRT Services Framework Function: Vulnerability remediation development (3282999a-09d1-5d99-9d23-4773611775be) FIRST CSIRT Services Framework 1