Identification should include resources such as
NIST National Vulnerability Database (NVD) (
https://nvd.nist.gov/
)
Industrial Control Systems-Computer Emergency Response Team (ICS-CERT) Advisories (
https://ics-cert.us-cert.gov/advisories
)
vendor websites.
Process/Skill Questions:
Why are vendor websites valuable resources when identifying vulnerability information?
How is the NIST NVD helpful?