Skip to content

Evidence request lists

ISO/IEC 29147:2018

Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Clause 1-4: Introduction

29147-1
Scope

Guidelines for vendors on receiving and disseminating vulnerability information

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-3
Terms and definitions

Vulnerability disclosure terminology including vulnerability, reporter, vendor, and coordinator

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-4
Abbreviated terms

Abbreviations used in the vulnerability disclosure standard

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
30111-1
Scope

Requirements and recommendations for vendors on how to process and remediate reported potential vulnerabilities

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
30111-3
Terms and definitions

Terminology for vulnerability handling including vulnerability, vendor, CSIRT/PSIRT, and remediation

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
30111-4
Abbreviated terms

Abbreviations used throughout the vulnerability handling processes standard

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC

Clause 5: Vulnerability Disclosure Concepts

29147-5.10
Disclosure Records and Retention

The vendor maintains comprehensive records of received reports, handling decisions, and published advisories for an appropriate retention period.

Artefacts an auditor will ask for
  • Vulnerability case management system with full case history
  • Retention schedule aligned to legal and regulatory requirements
  • Backup and recovery for the vulnerability database
  • Auditor access procedure
  • Annual disclosure metrics report
Where this commonly fails
  • Records held in disparate spreadsheets and email
  • No retention schedule, records purged inconsistently
  • Loss of historical advisories during website migration
  • Metrics not aggregated for management review
29147-5.11
Researcher Safe Harbour and Legal Posture

The vendor commits in policy not to pursue legal action against finders who follow the published disclosure rules in good faith.

Artefacts an auditor will ask for
  • Safe harbour clause referencing applicable jurisdictions
  • Legal review record of the VDP
  • Internal escalation path before any legal action
  • Training for legal counsel on coordinated disclosure norms
  • Public statements reaffirming researcher protection
Where this commonly fails
  • Standard cease-and-desist sent before triage assessment
  • Safe harbour silent on third-party platforms
  • No legal sign-off on the VDP
  • Conflicting terms in product EULA reserving litigation rights
29147-5.4
Finder Communication and Coordination

The vendor maintains structured, timely communication with the finder across the lifecycle of the report including status updates, clarifications, and credit decisions.

Artefacts an auditor will ask for
  • Status update cadence policy (for example every 14 days)
  • Finder communication log per case
  • Credit and recognition policy
  • Hall of fame or acknowledgement page
  • Escalation contact for unresolved disputes
Where this commonly fails
  • Communication drops once internal remediation begins
  • No process to credit researchers who request recognition
  • Public statements made before finder agreement
  • Conflicting messages from PR and security teams
29147-5.5
Coordinated Disclosure Timeline

The vendor establishes a coordinated disclosure timeline balancing remediation readiness with finder and user expectations.

Artefacts an auditor will ask for
  • Default disclosure window (commonly 90 days) documented in policy
  • Per-case disclosure plan with target dates
  • Extension request and approval records
  • Coordination minutes with finder agreeing to timeline
  • Sign-off from product, legal, and communications
Where this commonly fails
  • Open-ended disclosure with no committed date
  • Extensions granted without finder consent
  • No internal owner accountable for the timeline
  • Disclosure rushed before fix availability
29147-5.6
Advisory Content and Quality

Published advisories contain sufficient information for users to assess risk, identify affected versions, and apply mitigations or fixes.

Artefacts an auditor will ask for
  • Advisory template covering affected products, CVE, CVSS, summary, mitigation, and fix
  • Sample published advisories from prior 12 months
  • Editorial review checklist signed before publication
  • Translation or localisation records where required
  • CVE assignment via CNA or coordinator
Where this commonly fails
  • Advisories omit affected version ranges
  • Mitigation steps absent for users who cannot patch immediately
  • No CVE assigned for material vulnerabilities
  • Inconsistent advisory format across product lines
29147-5.7
Multi-Party Coordination

The vendor coordinates disclosure with upstream suppliers, downstream integrators, and coordinators when a vulnerability spans multiple parties.

Artefacts an auditor will ask for
  • Coordinator engagement records (for example CERT/CC, JPCERT/CC)
  • Upstream and downstream notification list per case
  • NDA or confidentiality agreements with coordinating parties
  • Joint advisory drafts with version control
  • Embargo and lift schedule
Where this commonly fails
  • No identification of downstream OEMs reusing the affected component
  • Embargoes broken by one party before agreed lift
  • Coordinator brought in late after public disclosure
  • No process for cross-vendor issues in shared libraries
29147-5.8
Confidentiality of Reports

The vendor protects the confidentiality of vulnerability information until coordinated disclosure to prevent exploitation in the wild.

Artefacts an auditor will ask for
  • Access list to vulnerability tracking system limited to need-to-know
  • Classification scheme for vulnerability records
  • Encrypted storage and transmission controls
  • Audit log of who viewed and modified each case
  • Leak response procedure
Where this commonly fails
  • Broad engineering access to all open vulnerabilities
  • Discussions in unencrypted chat channels
  • No audit trail in tracking system
  • Customer support staff inadvertently exposed to confidential reports
29147-5.9
Post-Disclosure Monitoring

After public disclosure the vendor monitors exploitation activity, user adoption of fixes, and feedback to inform future improvements.

Artefacts an auditor will ask for
  • Threat intelligence subscription covering exploitation reports
  • Patch adoption telemetry where supported
  • Customer feedback channel for advisory clarity
  • Post-disclosure retrospective for high-severity cases
  • CISA KEV catalogue cross-check
Where this commonly fails
  • No tracking of whether issued patch is adopted
  • Exploitation in the wild reported by third parties before vendor awareness
  • Retrospectives only for incidents not vulnerabilities
  • No metric on time from disclosure to patch availability

Clause 6: Receiving Vulnerability Reports

29147-6.1
General receiving guidelines

General guidelines for vendors to set up processes to receive vulnerability reports

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.2
Vulnerability report contents

Expected contents and format of vulnerability reports including technical details

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.3
Initial assessment

Guidelines for initial assessment and triage of received vulnerability reports

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.4
Further investigation

Guidelines for investigating and verifying reported vulnerabilities

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.5
Ongoing communication

Maintaining communication with reporters throughout the handling process

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.6
Coordinator involvement

When and how to involve a coordinator in the vulnerability disclosure process

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-6.7
Operational security

Maintaining operational security when handling vulnerability information

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC

Clause 7: Publishing Vulnerability Advisories

29147-7.3
Advisory publication guidelines

Guidelines for publishing vulnerability advisories to affected parties and the public

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-7.4
Advisory content elements

Required and recommended elements in published vulnerability advisories

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-7.5
Communication channels

Channels and methods for communicating vulnerability advisory information

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-7.6
Advisory format

Format standards and machine-readable formats for vulnerability advisories

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-7.7
Advisory authenticity

Ensuring authenticity and integrity of published vulnerability advisories

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-7.8
Remediation information

Including remediation guidance including patches, workarounds, and mitigation steps

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC

Clause 8-9: Coordination and Disclosure Policy

29147-8.1
Coordination general

General guidelines for coordinating vulnerability disclosure among multiple parties

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-8.2
Vendors playing multiple roles

Handling situations where vendors serve as both vendor and coordinator

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-9.1
Vulnerability disclosure policy development

Developing a vulnerability disclosure policy including required and recommended elements

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-9.2
Contact mechanisms and scope

Establishing contact mechanisms, secure communication options, and defining disclosure scope

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC
29147-9.3
Communication expectations and timelines

Setting communication expectations and timelines in the disclosure policy

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure tracker and case files
  • Advisory templates and published advisories
  • Vulnerability handling SOP and team roster
  • Post-release lessons-learned records
Where this commonly fails
  • No published vulnerability reporting channel
  • Coordination handoffs to upstream vendors are ad hoc
  • Advisories lack remediation detail and authenticity proof
  • Post-release lessons learned not fed back to SDLC

Communication

29147-5.13
External Stakeholder Notification

The vendor notifies regulators, large customers, and partners under contractual or regulatory obligations before or at public disclosure.

Artefacts an auditor will ask for
  • Stakeholder notification matrix by jurisdiction and customer tier
  • Pre-disclosure briefing template
  • Regulatory filing evidence where required
  • Customer NDA register for advance notice
  • Distribution list maintained current
Where this commonly fails
  • Notification list outdated, key customers missed
  • Regulatory disclosure deadlines missed
  • Inconsistent advance notice creating perceptions of favouritism
  • No record of which stakeholders received advance copy

Coordination

29147-5.14
Embargo Management

Embargoes on vulnerability information are time-limited, documented, and managed to balance protection of users and timely disclosure.

Artefacts an auditor will ask for
  • Embargo agreement template
  • Embargo register with start, end, and parties
  • Procedure for handling embargo breaches
  • Lift coordination playbook
  • Internal review for embargoes longer than 90 days
Where this commonly fails
  • No embargo agreements in writing
  • Indefinite embargoes left in place
  • No defined breach response
  • Embargo lift uncoordinated across time zones

Governance

29147-5.15
Programme Governance and Roles

The vendor assigns accountability for the vulnerability disclosure programme and reviews its effectiveness at management level.

Artefacts an auditor will ask for
  • PSIRT charter and reporting line
  • Defined roles for intake, triage, remediation lead, and communications
  • Quarterly programme review minutes
  • KPI dashboard (time to acknowledge, fix, publish)
  • Annual management review report
Where this commonly fails
  • PSIRT reports into engineering without independent voice
  • No KPIs measured, only anecdotal performance
  • Programme not reviewed by senior management
  • Roles unfilled during staff transitions

Intake

29147-5.2
Receipt of Vulnerability Reports

The vendor provides a reliable, documented channel for external finders to submit vulnerability reports and acknowledges receipt within a defined timeframe.

Artefacts an auditor will ask for
  • Dedicated email alias (security@) or web form for vulnerability reports
  • PGP key or equivalent for encrypted submissions
  • Acknowledgement template with target response time (typically 1 to 3 business days)
  • Intake ticket log with received timestamp
  • Reporter contact register
Where this commonly fails
  • Reports routed to general support and lost in queue
  • No encrypted submission option
  • Acknowledgements exceed published SLA
  • No unique identifier assigned at intake

People

29147-5.16
Training and Awareness

Personnel involved in vulnerability handling and external communications receive role-specific training on the disclosure process and confidentiality requirements.

Artefacts an auditor will ask for
  • Role-based training curriculum for PSIRT, engineering, legal, and PR
  • Annual training completion records
  • Tabletop exercise reports
  • Onboarding checklist for new joiners
  • Refresher training schedule
Where this commonly fails
  • Training only on day one, no refresh
  • PR and legal staff not included in training
  • No tabletop exercises run in prior year
  • Records not retained for audit

Policy and Scope

29147-5.1
Vulnerability Disclosure Policy

The vendor establishes and publishes a vulnerability disclosure policy that defines scope, points of contact, expectations, and protections for external reporters.

Artefacts an auditor will ask for
  • Published vulnerability disclosure policy (VDP) on vendor website
  • Scope statement covering in-scope products, services, and versions
  • Safe harbour and legal protection language for good-faith researchers
  • Policy approval record signed by accountable executive
  • Annual policy review evidence
Where this commonly fails
  • Policy buried in legal pages without discoverability via /.well-known/security.txt
  • No safe harbour clause, deterring researchers
  • Scope ambiguity covering only some product lines
  • Stale policy with no review cadence

Programme

29147-5.12
Bug Bounty Programme Integration

Where the vendor operates a bug bounty programme it is integrated with the coordinated disclosure process and shares intake, triage, and remediation paths.

Artefacts an auditor will ask for
  • Bounty platform configuration (for example HackerOne, Bugcrowd, Intigriti)
  • Reward schedule by severity
  • Integration ticket flow into internal vulnerability tracker
  • Annual programme performance report
  • Reconciliation between bounty payouts and finance
Where this commonly fails
  • Bounty platform operating in parallel without ticket sync
  • Reward decisions inconsistent with documented schedule
  • No taxation or contractor compliance for payouts
  • Scope mismatch between VDP and bounty programme

Triage

29147-5.3
Initial Triage and Verification

The vendor verifies reported vulnerabilities, assesses validity and severity, and communicates triage outcomes to the finder.

Artefacts an auditor will ask for
  • Triage procedure with validity, severity, and exploitability checks
  • CVSS v3.1 or v4.0 scoring records per report
  • Reproduction evidence in triage ticket
  • Finder notification of triage outcome
  • Decision log for duplicate, out-of-scope, or invalid reports
Where this commonly fails
  • No documented triage criteria leading to inconsistent decisions
  • Severity scored by single reviewer without peer check
  • Finder left without status for weeks during triage
  • Duplicates not linked to master case
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.