Commit 9a0f8a82 authored by Aeva Black's avatar Aeva Black
Browse files

fix should/shall in 4.3.6.1

parent e9585129
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -444,10 +444,12 @@ The operating system can choose which thread to schedule based on factors such a

Operating Systems provide essential functionality for securely updating hardware and software products which integrate the operating system. Therefore, the manufacturer of the Operating System shall document and maintain a policy for handling vulnerabilities in accordance with << NORMATIVE REFERENCE TO PT3 HERE>>.

For operating systems that rely on third-party open source software components, the manufacturer's vulnerability handling process should take into account << INFORMATIVE REFERENCE TO FIRST GUIDANCE HERE >>. In particular, it should include:
For operating systems that rely on third-party open source software components, the manufacturer's vulnerability handling process shall include:
1. recording of all third-party open source components by name, version, source location, and hash-based identifier;
1. proactive monitoring of external sources for vulnerability disclosure regarding the third-party open source components;

This should be accomplished by implementing additional vulnerability handling steps according to common industry standards such as << INFORMATIVE REFERENCE TO FIRST GUIDANCE HERE >>, and by relying on accepted standards for precise software identification, such as << INFORMATIVE REFERENCE TO PURL and SWHID HERE >>.

#### 4.3.6.2 Enabling Vulnerability Handling in Integrated Products 

When Operating Systems are integrated into subsequent products in a supply chain, vulnerabilities in the operating system may have a particularly high impact on the security characteristics of the final product. Therefore, manufacturers of Operating Systems intended for integration in subsequent products have a responsibility to enable the vulnerability handling processes of manufacturers which depend upon them.