The Time Has Come to Hack the Planet
Today marks an exciting development in the often monotonous rehashing of vulnerability disclosure. The ISO standard that began about 11 years ago with the emotionally loaded title “Responsible Vulnerability Disclosure,” and was finally published in early 2014 as ISO/IEC 29147 Vulnerability disclosure, is now available for download at no cost.
One of the key criticisms of the ISO standard was that vendors who wanted to follow it had to pay for it. In fact, the lack of public free availability of that standard was one of the reasons that the U.S. Department of Commerce launched a multistakeholder process under NTIA to increase collaboration between security researchers and organizations in vulnerability disclosure.
Now, for the first time, vendors can follow an internationally recognized guide, albeit in ISO-speak, on how to receive vulnerability reports from people or organizations, how to distribute advisory information on the impact of the issue, and how to mitigate or fix it.