Glossary · OT security engineering
Security advisory
Also known as: Vulnerability advisory, Security bulletin
German: Sicherheitshinweis
In product security, a security advisory is a document published by a manufacturer or coordinator that informs users about a vulnerability in specific products and versions, its severity and impact, and the available fixes, mitigations and workarounds. Machine-readable advisories can use the Common Security Advisory Framework (CSAF).
- Security engineering
- OT security
- Technical documentation
In one sentence
A security advisory informs users about a vulnerability in specific products and versions, its severity and the available fixes and mitigations.
Example
The advisory lists the affected firmware versions of a switch family, CVE IDs and CVSS vectors, the fixed version, and a workaround of disabling the web interface until the update is installed.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
- The SBOM under BSI TR-03183-2: an inventory, not a vulnerability reportWhat does BSI TR-03183-2 require of a software bill of materials, and how does it relate to the CRA?UKDeutsch
- Receiving vulnerability reports under BSI TR-03183-3: report, notification, advisoryWhat does BSI TR-03183-3 expect a manufacturer to have in place before the first vulnerability report arrives?UKDeutsch
How it applies
- Product development: Advisories are the output of vulnerability handling. They should name affected products and versions precisely, describe the vulnerability without giving attackers a recipe, and give the fix and mitigations for users who cannot update immediately.
- Operation: Operators match advisories to their Asset inventory. Machine-readable formats such as CSAF allow automated matching, which helps with large installed bases.
- Compliance: The CRA requires manufacturers to inform users about fixed vulnerabilities and actively exploited vulnerabilities, including mitigations.
- Documentation: A security advisory is a piece of technical documentation. Use a consistent template, controlled terminology and version history, and keep product names identical to those on type plates and in manuals. Technical writers can own the template and review the wording.
Security advisory vs. safety notice
A security advisory addresses vulnerabilities to cyberattacks. A safety notice or field safety notice addresses a risk of harm from the product. When a vulnerability can affect safety, both may be needed; distinguish them clearly, as with a Warning message in the manual.