ETSI releases Report on Coordinated Vulnerability Disclosure – ETSI

As of early 2022, only about 20% of ICT and IoT companies maintain a publicly identifiable dedicated channel for reporting serious security vulnerabilities, leaving many smaller firms and non-regulated products without formal processes to handle third-party issues. ETSI EN 303 645 mandates a Vulnerability Disclosure (CVD) scheme as a critical baseline requirement to ensure ongoing security after a product is deployed, ranking it just below the prevention of default passwords in importance. The new ETSI technical report provides SMEs and larger enterprises with guidance on establishing triage processes, managing third-party vulnerabilities, and adopting a formal disclosure policy to prevent reputational damage from public exploits. By implementing these structured CVD schemes, organizations can effectively identify and resolve flaws like the Log4j bug before they lead to widespread security events.

Source: https://www.etsi.org/newsroom/press-releases/2029-2022-02-etsi-releases-report-on-coordinated-vulnerability-disclosure/

Keywords: vulnerability disclosure, IoT security, security lifecycle, third-party vulnerabilities, security researchers

Previous Article

ETSI launches new education programme for the next generation of ICT standards professionals - ETSI

Next Article

MEC is ramping up with Phase 3 work on Multi-access Edge Computing - ETSI

StandardsGPT

Ask your questions!