Maintain
Product security and CRA cell
Maintain governance of products, vulnerabilities, dependencies, patches, incidents and evidence within a continuous organisation.
In your situation
What the scoping will need to take into account.
Operated capacity
Operate product security sustainably, from versions to vulnerabilities.
The unit links each report and vulnerability to the affected versions, remediation decisions, communications and evidence from the product lifecycle.
Subject of the work
The unit links versions, vulnerabilities, patches and product decisions.
How it actually unfolds
Set up a capability that remains operable over time.
Recurring product coordination cell linking reports, vulnerabilities, versions, patches, support and evidence.
Product and engineering teams qualify and then execute the decisions; communication and escalation roles remain assigned.
Portfolio and versions, components, reporting channels, vulnerabilities, incidents, support policies and obligations to be qualified.
The pace follows the versions released, the reports received, the correction windows and the notification deadlines applicable to the product concerned.
Operating cadence
Maintain product governance connected to engineering decisions.
Status maintained
The living record of product security decisions.
The register retains, for each product, the versions released, the support period and the security decisions still open.
The process follows a report from receipt through to qualification, remediation and coordinated communication.
Architecture, SBOM, tests, vulnerabilities and risk decisions remain linked to versions actually distributed.
The schedule cross-references end-of-support dates, component reviews, processing exercises and the portfolio's documentary deadlines.
Scoping the engagement
Size the team to match the portfolio and support periods.
The portfolio, support periods and reporting channels make it possible to size the ongoing governance of versions and vulnerabilities.

