Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning Common Vulnerabilities and Exposures (CVE) identifiers to reported vulnerabilities
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Originally reported by CISA Alerts
0 comments
No comments yet. Be the first to start the discussion.