A Security Practices Evaluation Framework

Post-Release Vulnerabilities


Description

Vulnerabilities discovered after the software is released should be studied for how they could be identified and resolved sooner.

Definition

Vulnerabilities found in released software.

Data Collection

When a vulnerability is found in released software, record its per-vulnerabilty attributes and mark the Phase as ‘Post-Release’. Count total number of vulnerabilities found in released software.