← All assessment areas

ASSESSMENT AREAS

Product security

A vulnerable component has been found. Which product is affected, and what happens next?

Explore a scenario connecting software components, vulnerability review, VEX and a PSIRT case. Follow the path from a technical finding to a reasoned decision.

Explore the example

A practical situation

The component inventory of a synthetic product contains a component linked to a reported vulnerability. The relevance of the finding must be assessed before a conclusion about the product is reached.

Illustrative example · synthetic data

From the problem to the next step

An illustrative scenario using synthetic data, not a view of a real client’s operations.

  1. 01Component in the SBOM
  2. 02Finding
  3. 03Relevance assessment
  4. 04VEX / PSIRT
  5. 05Decision and evidence

What the example shows

The finding is linked to the component and a review case. While relevance is being assessed, the product is not marked as secure; the decision must have a rationale and supporting evidence.

Example outputs

  • Component and finding overview
  • PSIRT case and decision trail

A VEX statement alone does not prove the absence of risk. Regulatory scope and response decisions require separate confirmation.

Illustrative example · synthetic data

Does this problem sound familiar?

Request Pro-Demo access and tell us which area interests you. The SION team will confirm which scenario you can explore.