Knowledgebase

Handling Vulnerability Reports From Others Print

  • 0

When someone tells you about a weakness.

WHY IT MATTERS

People find weaknesses in your systems and how you respond determines whether they tell you.

WHAT TO ESTABLISH

A published route for reporting security issues.

WHAT IT SHOULD PROVIDE

A contact What information to include What the reporter can expect Confirmation that good-faith reporting is welcomed

WHY THAT LAST POINT

Reporters fear legal consequences and many stay silent.

WHAT TO PUBLISH

A clear statement that good-faith research and reporting will not be pursued.

WHY

It is what produces reports rather than silent disclosure elsewhere.

WHAT TO DO ON RECEIVING A REPORT

Acknowledge it promptly Thank the reporter Verify the issue Assess its severity Fix it Tell the reporter what happened

WHY ACKNOWLEDGEMENT PROMPTLY

Silence causes reporters to assume they are being ignored, and to publish.

WHAT TO AVOID

Threatening the reporter Dismissing the report without verification Ignoring it Fixing it silently without acknowledgement

WHY THREATS FAIL COMPLETELY

They become public, they damage reputation severely, and they discourage future reports.

WHAT TO ESTABLISH ABOUT DISCLOSURE

When the issue may be discussed publicly.

WHAT IS REASONABLE

Time to fix, proportionate to complexity.

WHAT TO AGREE

A timescale with the reporter.

WHY AGREE

Unilateral demands for indefinite silence are not respected.

WHAT TO DO IF YOU CANNOT FIX IT QUICKLY

Explain why, and what interim measures exist.

WHAT TO CONSIDER

Recognising reporters publicly, with their permission.

WHY

It costs nothing and it encourages reporting.

WHAT TO ESTABLISH INTERNALLY

Who handles these reports.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot