THIS IS A SAMPLE! Feel free to use or modify it for your own use! Want a Policies and Procedures Wiki like this? Sign up for a Staff.Wiki trial by clicking here.
Third-Party System Flaw Incident Reporting
Third-party system flaws must be identified, reported, and corrected in a timely manner.
All software and firmware have potential flaws. Many vendors work to remedy those flaws by releasing vulnerability information and updates to their software and firmware. Contractors must have a process to review relevant vendor notifications and updates about problems or weaknesses. After reviewing the information, the contractor must implement a patch management process that allows for software and firmware flaws to be fixed without adversely affecting the system functionality. Contractors must define the time frames within which flaws are identified, reported, and corrected for all systems.
- Please use the Incident Report to register an identified vulnerability with a software product to ensure proper notification procedures are enacted.
- A Change Request form must be completed for any updates to software versions.
Want a Policies & Procedures Wiki like this? Sign up and try Staff.Wiki by clicking here.