Vulnerability Management Process
The vulnerability management process consists of five stages.
Stage 1 - Reception
When a report is received in the inbox, the submitter will be contacted to acknowledge receipt of the report within 24 business hours. PSIRT will do a first look at the information and work collaboratively with the submitter to confirm the nature, gather additional information, and ascertain appropriate remedial action.
Stage 2 - Verification
The verification of the product vulnerability will be independently assessed by a tester outside of the product development team in the suspected product(s). The PSIRT team will engage with product team(s) in the organization for the affected product(s). The product team and security subject matter experts will evaluate the vulnerability and work to reproduce the issue. Once it has been reproduced, it will be considered a valid issue. The PSIRT will create a Product Security Vulnerability Record with a unique internal tracking number for the security-related issue.
Stage 3 - Assessment
Rockwell Automation uses version 3.1 of the Common Vulnerability Scoring System (CVSS) as part of its standard process for evaluating all substantiated vulnerabilities in Rockwell Automation products. Multiple parameters are considered in the vulnerability assessment as detailed in figure 1. These are the Base Metrics for CVSS scoring and represent the intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments.
Each of these metrics as well as the rating choices shown are fully defined on the CVSS scoring site. The metrics assigned to the vulnerability are the output of the investigation of the vulnerability report by the PSIRT. Rockwell Automation will provide the base score upon disclosure of the vulnerability. Customers are encouraged to utilize this score as a baseline for prioritizing response but to also take into consideration the environment that the products are located within.
Figure 1: