Vulnerability management

Vaisala Product Security Practices Application Note

Document code
M213249EN-B
ft:locale
en-US
Content type
Security
Document type
Application note

Vaisala defines a vulnerability as an inherent weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source. Vaisala’s goal is to be aware of technical vulnerabilities and to manage them where possible, either directly or through other means.

Each Vaisala product and service-related vulnerability is treated as a security defect and is managed in product development according to team- or unit-specific defect management practices.

Information about vulnerabilities can come from internal or external sources. Internal sources are any type of testing done within Vaisala. Typical examples are:

  • Vulnerability scanning
  • Vulnerability management tools
  • Manual security testing

External sources can be, but are not limited to:

  • Customer-reported issues coming through Vaisala customer service channels or security@vaisala.com
  • External security assessments, including penetration tests
  • Public vulnerability announcements and security bulletins related to third-party software components

Vulnerabilities are rated and addressed according to defined processes. These include:

  • Risk assessment: Evaluating the potential impact and likelihood of exploitation
  • Prioritization: Addressing vulnerabilities based on their severity and potential impact
  • Remediation: Implementing fixes or mitigation to address vulnerabilities
  • Verification: Ensuring that vulnerabilities have been effectively addressed

When there is reasonable doubt to suspect that a product vulnerability could have caused an incident, such as an event of public disclosure of a zero-day vulnerability to a third-party software component used in a Vaisala product or service, a security incident is raised and investigated.