Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on collaborating with security researchers to identify, fix, and responsibly disclose vulnerabilities, ultimately improving product security and fostering trust.
The United States Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and international partners, has released a comprehensive set of guidelines for creating and maintaining a Coordinated Vulnerability Disclosure (CVD) program. These guidelines are intended for software manufacturers and online service providers to facilitate a productive and secure relationship with external security researchers. The core of the guidance centers around establishing a clear Vulnerability Disclosure Policy (VDP) and a defined process for handling reported vulnerabilities, including triage, remediation, and assigning Common Vulnerabilities and Exposures (CVE) identifiers. The document emphasizes the importance of leveraging third-party intermediaries, such as CISA or national computer security incident response teams, to assist with the CVD process, particularly when organizations lack the resources or expertise to manage it internally. This collaborative approach aims to improve product security by proactively addressing weaknesses before they can be exploited, and to build stronger relationships between security researchers and vendors. The guidance stresses the need for transparency and a commitment to responsible disclosure practices.