EN ISO/IEC 29147:2020 PDF
Information technology - Security techniques - Vulnerability disclosure (ISO/IEC 29147:2018)
Information technology - Security techniques - Vulnerability disclosure (ISO/IEC 29147:2018)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 42
- Дата публикации:
- 27 мая 2020 г.
- Издание:
- CEN/CENELEC EN 29147 edition 1 version 1
- ICS:
- 35.030
This document provides requirements and recommendations to vendors on the disclosure of vulnerabilities in products and services. Vulnerability disclosure enables users to perform technical vulnerability management as specified in ISO/IEC 27002:2013, 12.6.1[1]. Vulnerability disclosure helps users protect their systems and data, prioritize defensive investments, and better assess risk. The goal of vulnerability disclosure is to reduce the risk associated with exploiting vulnerabilities. Coordinated vulnerability disclosure is especially important when multiple vendors are affected. This document provides: — guidelines on receiving reports about potential vulnerabilities; — guidelines on disclosing vulnerability remediation information; — terms and definitions that are specific to vulnerability disclosure; — an overview of vulnerability disclosure concepts; — techniques and policy considerations for vulnerability disclosure; — examples of techniques, policies (Annex A), and communications (Annex B). Other related activities that take place between receiving and disclosing vulnerability reports are described in ISO/IEC 30111. This document is applicable to vendors who choose to practice vulnerability disclosure to reduce risk to users of vendors' products and services.
Abstract
Overview
EN ISO/IEC 29147:2020 (ISO/IEC 29147:2018) - Information technology - Security techniques - Vulnerability disclosure - provides vendor-focused requirements and recommendations for responsibly handling and disclosing vulnerabilities in products and services. The standard’s primary goal is to reduce risk from exploited vulnerabilities by enabling coordinated vulnerability disclosure so users can perform effective technical vulnerability management (see ISO/IEC 27002:2013, clause 12.6.1).
Key topics and requirements
- Vulnerability handling process - guidance on preparation, receipt, verification, remediation development, release, post-release actions and embargo periods.
- Receiving reports - capability to receive and track vulnerability reports, acknowledgement, monitoring and secure communications.
- Verification and investigation - initial assessment, further investigation and ongoing communications with reporters and coordinators.
- Publishing advisories - advisory content and timing requirements, including advisory elements such as identifiers, date/time, title, overview, affected products, and intended audience.
- Stakeholder roles - defined roles for vendors, reporters, coordinators, and users, and their responsibilities in coordinated disclosure.
- Confidentiality and secure exchange - recommendations for protecting sensitive information while coordinating remediation.
- Policy and techniques - considerations for creating a vulnerability disclosure policy and practical techniques; illustrative examples are provided in Annex A (techniques/policies) and Annex B (communications).
- Relationship to other standards - describes how disclosure activities relate to ISO/IEC 30111 (vulnerability handling/testing) and ISO/IEC 27002 (information security practices).
Applications and who should use it
- Vendors and product teams - to establish or improve a formal vulnerability disclosure policy and process for products, services, and components.
- Security/PSIRT teams - to standardize report intake, verification workflows, advisory publication, and communication with researchers and customers.
- Incident response and CSIRTs - to coordinate multi-vendor disclosures and reduce cross-product exploitation risk.
- Security researchers and coordinators - to understand vendor expectations for report format, timelines, and confidentiality.
- Risk and compliance managers - as part of broader vulnerability management aligned with ISO/IEC 27002 and organizational risk reduction.
Related standards
- ISO/IEC 30111 - technical processes between receiving and disclosing vulnerability reports (testing and remediation handling).
- ISO/IEC 27002 - information security controls and vulnerability management context (clause 12.6.1).
EN ISO/IEC 29147:2020 is essential reading for organizations aiming to implement coordinated vulnerability disclosure, publish clear vulnerability advisories, and reduce exploitation risk across products and services.
Технические детали
- Технический комитет
- CEN/CLC/TC 13 - Cybersecurity and Data Protection
- SKU
- EN ISO/IEC 29147:2020
Похожие стандарты
Упомянутые в описании и другие стандарты EN
SIST EN ISO/IEC 30111:2020
ДействующийInformation technology - Security techniques - Vulnerability handling processes (ISO/IEC 30111:2019)
Overview EN ISO/IEC 30111:2020 (ISO/IEC 30111:2019) specifies requirements and recommendations for processing and remediating reported potential vulnerabilities in products and services. Intended pri…
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
EN ISO 6599-1:2026
ДействующийPackaging - Conditioning for testing - Part 1: Paper sacks (ISO 6599-1:2026)
Overview EN ISO 6599-1:2026 - Packaging - Conditioning for testing - Part 1: Paper sacks is a key international standard developed by CEN and ISO. This document defines the conditioning atmospheres a…
EN ISO 4885:2026
ДействующийFerrous materials - Heat treatments - Vocabulary (ISO 4885:2026)
Overview EN ISO 4885:2026 - Ferrous Materials – Heat Treatments – Vocabulary is an international standard developed by CEN, aligning with ISO 4885:2026. This document provides comprehensive definitio…
EN ISO/IEC 29151:2026
ДействующийInformation security, cybersecurity and privacy protection - Controls, requirements, and guidance for persona…
Overview EN ISO/IEC 29151:2026 specifies controls, requirements, and guidance to ensure the proper protection of personally identifiable information (PII) within the fields of information security, c…
EN ISO 9693:2026
ДействующийDentistry - Compatibility testing for metal-ceramic and ceramic-ceramic systems (ISO 9693:2026)
Overview EN ISO 9693:2026 - Dentistry: Compatibility Testing for Metal-Ceramic and Ceramic-Ceramic Systems establishes internationally recognized requirements and test methods for evaluating the ther…
EN ISO 26082-1:2026
ДействующийLeather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale…
Overview EN ISO 26082-1:2026 is a European standard titled "Leather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale) method" adopted by CEN. This…
EN ISO/IEEE 11073-10101:2020/A1:2026
ДействующийHealth informatics - Device interoperability - Part 10101: Point-of-care medical device communication - Nomen…
Overview EN ISO/IEEE 11073-10101:2020/A1:2026 is an amendment to the internationally recognized standard for health informatics and device interoperability, focusing specifically on the nomenclature…