PD ISO/IEC TR 5895:2022 PDF
Cybersecurity. Multi-party coordinated vulnerability disclosure and handling
Cybersecurity. Multi-party coordinated vulnerability disclosure and handling
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Дата публикации:
- 31 августа 2022 г.
- ICS:
- 35.030
- SKU:
- PD ISO/IEC TR 5895:2022
Abstract
1 Scope This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating:
— The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation 2 development, release, post-release) in MPCVD settings.
— Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111).
— The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings.
Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes.
Похожие стандарты
Упомянутые в описании и другие стандарты PD