Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Maintain

Maintain

Product security and CRA cell

Maintain governance of products, vulnerabilities, dependencies, patches, incidents and evidence within a continuous organisation.

In your situation

What the scoping will need to take into account.

Operated capacity

Operate product security sustainably, from versions to vulnerabilities.

The unit links each report and vulnerability to the affected versions, remediation decisions, communications and evidence from the product lifecycle.

Subject of the work

The unit links versions, vulnerabilities, patches and product decisions.

Demonstration example
01Operate the PSIRT and coordinated disclosureProduct register
02Track vulnerabilities and dependenciesVulnerability process
03Maintain documentation and supportEvidence file
04Prepare the elements required for notificationsPreparation timeline

How it actually unfolds

Set up a capability that remains operable over time.

Working format

Recurring product coordination cell linking reports, vulnerabilities, versions, patches, support and evidence.

Client-side mobilisation

Product and engineering teams qualify and then execute the decisions; communication and escalation roles remain assigned.

Starting elements

Portfolio and versions, components, reporting channels, vulnerabilities, incidents, support policies and obligations to be qualified.

Building the schedule

The pace follows the versions released, the reports received, the correction windows and the notification deadlines applicable to the product concerned.

Operating cadence

Maintain product governance connected to engineering decisions.

01Operate the PSIRT and coordinated disclosureThe PSIRT assigns reports, protects the exchanges and coordinates the disclosure decision with the relevant roles.
02Track vulnerabilities and dependenciesVulnerabilities and components are linked to the corresponding products, versions, exploitability status and remediation decisions.
03Maintain documentation and supportDocumentation, support and maintenance periods evolve with the versions delivered rather than in files separate from the product.
04Prepare the elements required for notificationsThe elements required for a notification are prepared from qualified facts and submitted to the applicable approvals.

Status maintained

The living record of product security decisions.

AssetProduct register

The register retains, for each product, the versions released, the support period and the security decisions still open.

PlannedVulnerability process

The process follows a report from receipt through to qualification, remediation and coordinated communication.

To be reviewedEvidence file

Architecture, SBOM, tests, vulnerabilities and risk decisions remain linked to versions actually distributed.

MaintainedPreparation timeline

The schedule cross-references end-of-support dates, component reviews, processing exercises and the portfolio's documentary deadlines.

Scoping the engagement

Size the team to match the portfolio and support periods.

The portfolio, support periods and reporting channels make it possible to size the ongoing governance of versions and vulnerabilities.