gives guidelines for how to process and resolve potential vulnerability information in a product or online service. ISO/IEC 30111:2013 is applicable to vendors involved in handling vulnerabilities.