A.8.8
    Technological Controls

    Management of technical vulnerabilities

    Information about technical vulnerabilities of information systems in use should be obtained, the organization's exposure to such vulnerabilities should be evaluated and appropriate measures should be taken.

    Purpose

    To prevent exploitation of technical vulnerabilities.

    Implementation Guidance

    Implement vulnerability scanning regularly

    Subscribe to security advisories

    Assess and prioritize vulnerabilities based on risk

    Apply patches and updates in a timely manner

    Track vulnerability remediation

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.8 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.8 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.8 Management of technical vulnerabilities. Built for compliance professionals.

    Try ISMS Copilot free