+PSS-02.01AC

1. Overview

PSS-02.01AC

The procedures for identifying such vulnerabilities also include annual code reviews or security penetration tests by qualified external third parties.

Known vulnerabilities in externally related system components (e.g. operating systems) used for the development and provision of the cloud service but not going through the cloud service provider's software development process are the subject of criterion OPS-25 (Managing Vulnerabilities, Incidents and Errors - Vulnerability Scans).
Summary Standard

1.1 References

1.2 Identified Requirements

1.2 Related Regulation

2. Identified Requirements

Requirements
Source Requirement

3. Related Regulations

Regulations
Source Regulation
Impressum