The standard recommends that vendors put in place a process and an organizational structure to support vulnerability investigation and remediation. This includes developing a vulnerability handling policy and an organizational framework that can fully support the process.
