Identifies components and maintains a machine-readable SBOM (SSDF PS.3.2)
Remediates vulnerabilities rapidly and delivers timely updates (SSDF RV.2)
Performs static, dynamic, fuzzing, and penetration testing (SSDF PW.7, PW.8)
Publicly discloses vulnerabilities once fixes are available *(aligned with SSDF RV.1.3)
Maintains a coordinated vulnerability disclosure policy (SSDF RV.1.3)
Provides a dedicated contact for vulnerability reporting (SSDF RV.1.1)
Distributes secure and authenticated updates (SSDF RV.2.2)
Provides free and timely security updates (SSDF RV.2)
Performs continuous lifecycle cybersecurity risk assessments (SSDF PW.1, RV.3)
Maintains documentation and archives software versions (SSDF PS.3)
Ensures vulnerability management during the support period (SSDF PO.1.2)
Maintains a secure development, build, and test environment (SSDF PO.5)
Performs root-cause analysis and improves SDLC processes (SSDF RV.3)
Provide role-based training for personnel involved in secure software development (SSDF PO.2.2)
Define and maintain clear secure SDLC roles and responsibilities (SSDF PO.2.1)