Confirmed facts
Known versions, released patches, affected services or confirmed unaffected variants.
A software vendor reports a critical vulnerability. A cloud provider reports a cyber incident. A supplier points to an affected component.
Does this affect us specifically? What do we know for certain? What information is missing? And who needs to take ownership now?
Capture the date and time, sender, supplier, notification type, advisory ID, ticket or CVE, stated urgency and original source. Be able to trace later what was received and what was derived internally.
Connect a general warning to the actual product, service, platform, component, version, build, firmware, environment or tenant.
Check the application or business process, own product, site, customer, data, interfaces, connected systems and critical function that could be affected.
Known versions, released patches, affected services or confirmed unaffected variants.
Unclear exploitability, subcontractors, data or time period, provider update or closure information.
Rule of thumb: Missing information is not positive security evidence.
Depending on use and criticality, request exact affected products and versions, technical description, timing, exploitation status, patches or mitigation, impact, affected data/services, subcontractors, SBOM/VEX, next update and closure information.
Involve the relevant functions such as IT/information security, product security/development, procurement, data protection, quality/compliance, incident management, product owners and the appropriate approval authority. Assign one clear owner.
Document the incoming signal, provider and affected service or component, own dependency, facts, gaps, requested information, owner, immediate measures, decision or escalation, next review date and closure information.
For suppliers, SaaS and cloud services, software vendors and other external dependencies.
Learn more about Supplier Cybersecurity →When the component is part of your own product with digital elements, product and version relevance need to be assessed.
Learn more about the Cyber Resilience Act →