Overview
EN ISO/IEC 30111:2020 (ISO/IEC 30111:2019) specifies requirements and recommendations for processing and remediating reported potential vulnerabilities in products and services. Intended primarily for vendors, it defines a structured vulnerability handling process and an organizational framework to receive, verify, remediate and disclose vulnerability information. The standard is designed to be used together with ISO/IEC 29147 (vulnerability disclosure) and supports vendor accountability, secure product lifecycle practices, and responsible vulnerability management.
Key topics and requirements
- Scope and audience: Applicable to vendors, product teams, PSIRTs/CSIRTs, evaluators and procurers who need robust vulnerability management processes.
- Policy and leadership: Requires leadership commitment, documented vulnerability handling policy, and clear organizational roles, responsibilities and authorities.
- Organizational framework: Recommends establishing a vendor PSIRT (Product Security Incident Response Team) or CSIRT, defining mission, responsibilities and staff capabilities.
- Vulnerability handling phases:
- Preparation - readiness, tooling and coordination mechanisms.
- Receipt - intake and classification of external or internal reports (integrates with ISO/IEC 29147).
- Verification - validating and reproducing reported issues.
- Remediation development - designing, testing and approving fixes.
- Release - coordinated disclosure and distribution of remediation.
- Post-release - monitoring, feedback and lessons learned.
- Process monitoring and confidentiality: Ongoing monitoring of handling processes and protection of sensitive vulnerability information during triage and disclosure.
- Supply chain considerations: Addresses vulnerabilities that affect or originate from third-party components and suppliers.
- Cross‑references: Aligns with related standards such as ISO/IEC 29147 and references ISO/IEC 27000 series for terminology and broader information security management.
Practical applications
- Establishing or improving a vendor’s vulnerability management program, including PSIRT policies and operating procedures.
- Defining intake and triage workflows for external vulnerability reports (researchers, customers, partners).
- Ensuring coordinated, secure and auditable remediation and release practices for security fixes and advisories.
- Using as procurement criteria: customers and integrators can require vendors comply with ISO/IEC 30111 when evaluating product security assurance.
- Guiding evaluators and auditors who assess a vendor’s vulnerability handling maturity and compliance.
Who should use it
- Software and hardware vendors, SaaS providers and integrators
- PSIRT/CSIRT teams, security operations and product security engineers
- Security evaluators, auditors and assessors
- Procurement and risk teams setting security requirements for suppliers
Related standards
- ISO/IEC 29147 - Vulnerability disclosure (used in conjunction with 30111)
- References to ISO/IEC 27000 family and other IT security standards for terminology and information security alignment
Keywords: vulnerability handling processes, ISO/IEC 30111:2020, EN ISO/IEC 30111, PSIRT, CSIRT, vulnerability disclosure, vendor vulnerability management, remediation, supply chain security.