CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2606

As cited

Copy frozen at (site build).

vulnerabilities

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and international partners released joint guidance on coordinated vulnerability disclosure (CVD) programs for software manufacturers and service providers. The guidance covers best practices for designing CVD programs, establishing vulnerability disclosure policies, triaging and remediating vulnerabilities, assigning Common Vulnerabilities and Exposures (CVE) identifiers, and optionally engaging third-party intermediaries. Organizations implementing these practices can improve vulnerability management, strengthen researcher relationships, and enhance product security.

Why it matters: Software vendors and online service providers should review this guidance to establish or strengthen CVD programs, which enable constructive engagement with external security researchers and reduce the window of time vulnerabilities remain unpatched in customer environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary