Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-10-1

Cybersecurity requirements for technical vulnerabilities management must be defined, documented and approved

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-10-2

The cybersecurity requirements for technical vulnerabilities management must be implemented.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-10-3

  1. The cybersecurity requirements for technical vulnerabilities management must include at least the following:
    1. Periodic vulnerabilities assessments.
    2. Vulnerabilities classification based on criticality level.
    3. Vulnerabilities remediation based on classification and associated risk levels.
    4. Security patch management.
    5. Subscription with authorized and trusted cybersecurity resources for up-to-date information and notifications on technical vulnerabilities.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-10-4

The cybersecurity requirements for technical vulnerabilities management must be reviewed periodically.