Vaisala defines a vulnerability as an inherent weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source. Vaisala’s goal is to be aware of technical vulnerabilities and to manage them where possible, either directly or through other means.
Each Vaisala product and service-related vulnerability is treated as a security defect and is managed in product development according to team- or unit-specific defect management practices.
Information about vulnerabilities can come from internal or external sources. Internal sources are any type of testing done within Vaisala. Typical examples are:
- Vulnerability scanning
- Vulnerability management tools
- Manual security testing
External sources can be, but are not limited to:
- Customer-reported issues coming through Vaisala customer service channels or security@vaisala.com
- External security assessments, including penetration tests
- Public vulnerability announcements and security bulletins related to third-party software components
Vulnerabilities are rated and addressed according to defined processes. These include:
- Risk assessment: Evaluating the potential impact and likelihood of exploitation
- Prioritization: Addressing vulnerabilities based on their severity and potential impact
- Remediation: Implementing fixes or mitigation to address vulnerabilities
- Verification: Ensuring that vulnerabilities have been effectively addressed
When there is reasonable doubt to suspect that a product vulnerability could have caused an incident, such as an event of public disclosure of a zero-day vulnerability to a third-party software component used in a Vaisala product or service, a security incident is raised and investigated.