Телефон: (011) 7541-421, 3409-301, 3409-335, 6547-293, 3409-310
E-mail: Продаја стандарда: prodaja@iss.rs Семинари, обуке: iss-edukacija@iss.rs Информације о стандардима: infocentar@iss.rs
Стевана Бракуса 2, 11030 Београд
Главни мени

ISO/IEC TR 5895:2022

Cybersecurity — Multi-party coordinated vulnerability disclosure and handling
17. 6. 2022.

Опште информације

60.60     17. 6. 2022.

ISO/IEC

ISO/IEC JTC 1/SC 27

Технички извештај

35.030  

енглески  

Куповина

Објављен

Језик на коме желите да примите документ.

Апстракт

This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating:
—    The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation[1] development, release, post-release) in MPCVD settings.
—    Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111).
—    The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings.
Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes.
 
[1] Remediation is a defined term used in ISO/IEC 30111 and ISO/IEC 29147. This document uses the term "remediation" and verb “remediate” in the context of this definition.

Животни циклус

ТРЕНУТНО

ОБЈАВЉЕН
ISO/IEC TR 5895:2022
60.60 Стандард објављен
17. 6. 2022.