Skip to main content

๐Ÿ’ผ A.16.1.3 Reporting information security weaknesses

Descriptionโ€‹

Employees and contractors using the organizationโ€™s information systems and services shall be required to note and report any observed or suspected information security weaknesses in systems or services.

Similarโ€‹

  • Internal
    • ID: dec-c-87fa1331

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ DE.DP-4: Event detection information is communicated3033
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ PR.IP-12: A vulnerability management plan is developed and implemented78

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags