ISO/IEC TR 5895:2022 PDF

ISO/IEC TR 5895:2022 PDF

Name:
ISO/IEC TR 5895:2022 PDF

Published Date:
07/01/2022

Status:
Active

Description:

Cybersecurity - Multi-party coordinated vulnerability disclosure and handling

Publisher:
International Org. for Standardization/International Electrotechnical Commission (Technical Report)

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$37.2
Need Help?

This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating:

— The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation[1] development, release, post-release) in MPCVD settings.

— Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111).

— The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings.

Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes.


File Size : 1 file , 1.7 MB
Number of Pages : 22
Published : 07/01/2022

History


Related products


Best-Selling Products

The New Yorker Book of Technology Cartoons
Published Date: 10/01/2000
$7.5