Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clarify the 96-hour vulnerability remediation process #8

Open
BenWilson-Mozilla opened this issue Apr 1, 2022 · 1 comment
Open

Comments

@BenWilson-Mozilla
Copy link
Contributor

Occasionally, the NetSec group has received comments that the 96-hour process for remediation of critical vulnerabilities in section 4.f. needs to be clarified.

@clintwilson
Copy link
Member

  1. Align with more common frameworks/timelines for vuln remediation
  2. Add requirements for non-critical vulns
  3. Ensure clarity of requirement
  4. Align scope (ideally through a scoping of the entire NCSSRs)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants