Joint guidance on cybersecurity outlines best practices for coordinated vulnerability disclosure programs

International guidance aims to standardize vulnerability transparency

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers is a 12-page document providing guidance for identifying and reporting cyber vulnerabilities. Issued on July 15, it outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities.

Developed by the Cybersecurity & Infrastructure Agency (CISA), the National Security Agency (NSA) and other international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a CVD program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning common vulnerabilities and exposures (CVE) identifiers to reported vulnerabilities.

The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program. By implementing a robust CVD program aligned with this guidance, organizations can work transparently and collaboratively with security researchers to remediate vulnerabilities, build constructive relationships, enhance product security while improving vulnerability management processes and demonstrate their dedication to protecting customers.

"The July 15 joint guidance from CISA, Netherlands, Japan and UK aims to help software manufacturers and online service providers understand the need for transparent communication and coordination with security researchers," said Andrew Chipman, director of governance, risk and compliance and information security officer at ProCircular. "Certainly, there is abuse of bug bounty programs, but this is not aimed at solving that. Rather, the aim is to make transparency the standard and create a culture where true security researchers have clear paths to safely disclose vulnerabilities."

Sign up for our eNewsletters
Get the latest news and updates