ED Decision 2023/010/R
Without prejudice to the definition of ‘information security event’ in Article 3 of Regulation (EU) 2023/203, those events that indicate the potential materialisation of unacceptable risks include both occurrences (i.e. anything that causes harm or has the potential to cause harm) and discovery of vulnerabilities. In fact, information security risks are associated with the potential that threats will exploit vulnerabilities, therefore the discovery of an exploitable vulnerability is an information security event.
In light of this, in the context of this Regulation:
— detection activities required under IS.AR.215(a) include vulnerability discovery;
— response activities required under IS.AR.215(b) include vulnerability management.
Loading collections...