Post-market security operations
Continuously detect, assess, communicate, and remediate cybersecurity issues in the field.
PSLF-07G7Continuous monitoringPhase 8 of 9
Gate
G7
Pending
Continuous monitoring
Target date
01 Feb 2027
Gate review
Open blockers
0
none recorded
Accountable
PSIRT Lead
Product, Safety, Quality, Legal, and Communications participate by severity
Monitor vulnerabilities and threats, triage incidents, patch, disclose, communicate, and reassess risk.
- Signals reach accountable triage within defined service levels.
- Changes trigger impact analysis across supported baselines.
- Released product baseline
- Monitoring sources and customer channels
- Incident, vulnerability, and patch plans
- 1Monitor vulnerabilities, exploits, threat intelligence, complaints, incidents, supplier notices, and field performance
- 2Triage using safety-aware risk and exploitability
- 3Coordinate disclosure and regulatory/customer communications
- 4Design, verify, distribute, and monitor patches
- 5Feed lessons and recurring root causes into the framework
- Vulnerability Management Plan
- Product Security Incident Response Plan
- Patch Management Plan
- Coordinated Vulnerability Disclosure Policy
- Post-market PSRA and VMR updates
- SLAs and escalation paths definedPending
- Every signal linked to affected products and componentsPending
- Communications and regulatory decisions recordedPending
- Risk and customer documentation remain currentPending
- Accountable
- PSIRT Lead accountable
- Supporting
- Product, Safety, Quality, Legal, and Communications participate by severity
- Signal (pending)
- Vulnerability (pending)
- Affected product (pending)
- Risk (pending)
- Decision (pending)
- Remediation (pending)
- Disclosure (pending)
- Verification (pending)
- Time to triage and remediate
- Supported products with current monitoring
- Overdue disclosures