Tietoturva nyt!
8.1.2010
CERT-FI vulnerability coordination policy
CERT-FI published today a document describing its vulnerability
coordination policy. The purpose of the policy is to describe the
goals and underlying assumptions of vulnerability coordination activities.
CERT-FI has been participating in vulnerability coordination projects since 2005. The most notable projects include the ISAKMP vulnerability of 2005, Archive Formats vulnerability of 2008 as well as vulnerabilities in XML Libraries and TCP Stacks (a.k.a. Sockstress) of 2009.
During these projects CERT-FI has recognized that there are mixed interpretations of the vulnerability coordination process flow and incompatible expectations among the players. CERT-FI's policy is an effort to spell out our position and to initiate discussion on the topic.
Comments are welcome at vulncoord (at) ficora.fi!
Lisätietoa
| Sivua päivitetty 08.01.2010 |
|
 |
Tulostusversio |