We need your consent to use the individual data so that you can see information about your interests, among other things. Click "OK" to give your consent.
Cybersecurity - Multi-party coordinated vulnerability disclosure and handling
Translate name
STANDARD published on 17.6.2022
Designation standards: ISO/IEC/TR 5895-ed.1.0
Publication date standards: 17.6.2022
SKU: NS-1066322
The number of pages: 14
Approximate weight : 42 g (0.09 lbs)
Country: International technical standard
Category: Technical standards ISO
This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating: — The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation[1] development, release, post-release) in MPCVD settings. — Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111). — The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings. Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes. [1] Remediation is a defined term used in ISO/IEC 30111 and ISO/IEC 29147. This document uses the term "remediation" and verb “remediate” in the context of this definition.
Do you want to make sure you use only the valid technical standards?
We can offer you a solution which will provide you a monthly overview concerning the updating of standards which you use.
Would you like to know more? Look at this page.
Latest update: 2025-06-30 (Number of items: 2 206 311)
© Copyright 2025 NORMSERVIS s.r.o.