Annex I, Part II, (2)
Mapped SPARTA techniques (7)
Techniques referencing this article
Address-and-remediate-without-delay obligations apply to design-flaw findings; manufacturers must close design-flaw exploitation paths under documented vulnerability handling.
Address-and-remediate-without-delay applies directly to identified code flaws; the obligation bounds the time-to-fix metric an exploitation adversary tries to outrun.
Address-and-remediate-without-delay applies to identified FSW vulnerabilities; the obligation bounds operational dwell time before remediation.
Address-and-remediate obligations cover OS-level defects, including misconfigurations around maintenance interfaces.
Address-and-remediate-without-delay is the temporal discipline that bounds the time-to-fix metric known-vulnerability exploitation tries to outrun.
Once a poisoned dependency is identified the manufacturer must address and remediate without delay under Annex I, Part II, (2), bounding the exploit window of dependency-confusion or typosquatting attacks.
Manufacturers must address and remediate vulnerabilities without delay; this is the operational discipline that bounds the time between disclosure and exploitation, which is the metric known-vulnerability reconnaissance is trying to outrun.