Vulnerability Disclosure
What is Vulnerability Disclosure?
The practice of reporting security vulnerabilities to the affected vendor or organisation so they can be patched before being exploited. Responsible disclosure policies define timelines and processes for vulnerability reporting.
Terms that appear alongside vulnerability disclosure
Each of these is named in at least one of the same controls as vulnerability disclosure. The number is how many controls name both.
- vulnerability 44 shared controls
- policy 16 shared controls
- cybersecurity 13 shared controls
- disclosure policy 12 shared controls
- nist 9 shared controls
- cisa 8 shared controls
- incident response 6 shared controls
- cve 6 shared controls
Frameworks that govern vulnerability disclosure
What the standards actually require on vulnerability disclosure
Requirements naming vulnerability disclosure across 6 standards, quoted from the control text.
Developing a vulnerability disclosure policy including required and recommended elements
29147-9.1 · Vulnerability disclosure policy development →AI Incident Reporting + Response is critical to learning + accountability + stakeholder protection per Japan AI Guidelines for Business + Hiroshima AI Process Code of Conduct + emerging AI Bill.
JP-AIG-Incident-Reporting-Response-AISI-METI-Notification-G7-Hiroshima-Reporting-Mechanism-Voluntary · Japan AI Guidelines AI Incident Reporting + Response + AISI/METI Notification + G7 Hiroshima Reporting Mechanism + Voluntary + AI Incident Database + OECD AI Incidents Monitor + Sector Regulator Notification + Coordinated Vulnerability Disclosure →FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD) Guidelines. IEP v2.0: a machine-readable extension of TLP that conveys handling restrictions + sharing permissions in structured form (JSON-LD).
FIRST-IEP-MPCVD · FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD) →A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.
ISM-1616 · A vulnerability disclosure program is implemented to assist with the secure development an →Maintain a public VDP that authorizes good-faith research and provides a safe channel for reporting.
SBD-9 · Establish a Vulnerability Disclosure Policy →Per PSTI: Vulnerability Disclosure Policy Publication + handling + acknowledgement + statutory contact.
UKPSTIACT-2 · Vulnerability Disclosure Policy and Reporting →Questions people ask about vulnerability disclosure
What is Vulnerability Disclosure?
Why is Vulnerability Disclosure important for compliance?
Which compliance frameworks address Vulnerability Disclosure?
Where can I learn more about Vulnerability Disclosure?
See how Vulnerability Disclosure applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.