Skip to main content

Implementation Guides: Operate Phase

Once a product is in the hands of customers, the focus shifts from building security in to maintaining, monitoring, updating, and evidencing it during the support period.

The Operate Phase covers the processes and infrastructure needed to receive vulnerability reports, triage findings, release fixes, communicate with customers, monitor security signals, and refresh evidence after product changes.

This section will help you answer questions like:

  • How do researchers, customers, or users report vulnerabilities?
  • How quickly should we assess, fix, roll out, and communicate security updates?
  • How can I detect and respond to attacks on my devices?
  • What post-market evidence should we retain?

Core Topics

  • Vulnerability Disclosure: Define public reporting routes, internal triage, vulnerability logs, reporting, customer communication, and retained evidence.
  • Patch Cadence & Rollback Strategy: Define remediation timing, support-period commitments, rollout controls, rollback rules, and release evidence.
  • Security Logging & Monitoring: Implement robust logging on both the device and backend services to detect, investigate, and respond to security incidents in the field.
  • CI/CD Hardening: Secure the build and release pipeline that produces, signs, scans, and delivers updates.

Use these guides with Secure OTA Updates, SBOM & VEX Workflows, and the Secure-by-Design Evidence Pack.