Cybersecurity vulnerability information is gathered and interpreted for the function, at least in an ad hoc manner
The organization should have a process for collecting, cataloging, and filtering vulnerability information from identified sources to separate out information that is relevant to the function.
Related Practices · Input From: Implementing THREAT-1a provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THREAT-1b, THREAT-1i, THREAT-1m.