IMANOR
 
Address: Angle Avenue Kamal Zebdi et Rue Dadi, Secteur 21, Hay Riad, Rabat 10100, Maroc
Télephone: +212537571948 Fax: +212537711773
E-mail: information@imanor.gov.ma
Menu principal

ISO/IEC TR 5895:2022

Cybersécurité — Divulgation et traitement de vulnérabilité coordonnée entre plusieurs parties

Cybersecurity — Multi-party coordinated vulnerability disclosure and handling
17 juin 2022

Informations générales

60.60     17 juin 2022

ISO/IEC

ISO/IEC JTC 1/SC 27

Technical Report

35.030  

anglais  

Buying

publiée

Language in which you want to receive the document.

Domaine d'activité

This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating:
—    The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation[1] development, release, post-release) in MPCVD settings.
—    Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111).
—    The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings.
Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes.
 
[1] Remediation is a defined term used in ISO/IEC 30111 and ISO/IEC 29147. This document uses the term "remediation" and verb “remediate” in the context of this definition.

Cycle de la vie

NOW

PUBLISHED
ISO/IEC TR 5895:2022
60.60 Normes publiées
17 juin 2022

Aperçu

Seules les sections informatives des projets sont accessibles au public. Pour voir le contenu complet, vous aurez besoin de membres du comité. Si vous êtes membre, veuillez vous connecter à votre compte en cliquant sur le bouton "Connexion".

Login