{"id":11469,"date":"2022-12-28T07:00:00","date_gmt":"2022-12-28T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=11469"},"modified":"2022-06-05T11:37:21","modified_gmt":"2022-06-05T19:37:21","slug":"security-inconsistent-policies-for-vulnerability-disclosures-creates-confusion","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-inconsistent-policies-for-vulnerability-disclosures-creates-confusion\/","title":{"rendered":"Security: Inconsistent Policies for Vulnerability Disclosures Creates Confusion"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Vulnerability disclosure is the reporting of security bugs and flaws in software and hardware products. Disclosure is usually made directly to the vendor or creator of the flawed product and the exact nature of the problem is typically not disclosed publicly until after the product has been fixed or patched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Product users typically would like to know as soon as possible about problems, but vendors prefer to not publicly announce until they have studied the problem and prepared a patch.  There is a give-and-take tension between these two groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/security.claroty.com\/1H-vulnerability-report-2021\" data-type=\"URL\" data-id=\"https:\/\/security.claroty.com\/1H-vulnerability-report-2021\">A group at Claroty<\/a> tracks reported vulnerabilities and creates biannual summary reports.   Hundreds of vulnerabilities are reported each year related to products from tens of vendors, many of which are classified as having either critical or high risk vulnerabilities.  But there is a huge variability in how the vulnerabilities were reported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bugcrowd.com\/resources\/guides\/ultimate-guide-to-vulnerability-disclosure\/\" data-type=\"URL\" data-id=\"https:\/\/www.bugcrowd.com\/resources\/guides\/ultimate-guide-to-vulnerability-disclosure\/\">BugCrowd creates<\/a> a guide for how to set up vulnerability disclosure programs. Many organizations establish policies for how they want vulnerabilities to be reported, but there is little consistency.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/ronbrash\/?originalSubdomain=ca\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/ronbrash\/?originalSubdomain=ca\">Ron Brash,<\/a> director of cyber security insights for Verve Industrial Protection, told EE Times, <a href=\"https:\/\/www.eetimes.com\/vulnerability-disclosure-programs-need-to-get-organized\/\" data-type=\"URL\" data-id=\"https:\/\/www.eetimes.com\/vulnerability-disclosure-programs-need-to-get-organized\/\">said that<\/a> &#8220;these programs [for reporting vulnerabilities] are all over the map: even U.S. federal agencies do their own thing. None of them are set up for maximum efficiency. It\u2019s all best effort. The large vendors often take ownership, but their multiple business units might all do it differently. Since each product can combine multiple products, the number of vendors multiplies even more.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Brash said that &#8220;Some open-source community projects are managing vulnerability disclosures fairly well. For instance, some parts of the Linux kernel are well managed; others not so much, and that\u2019s not even considering the overall Linux ecosystem. And when compared to other free and open-source software projects, or even various proprietary products, they too have highly variable security practices.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-inconsistent-policies-for-vulnerability-disclosures-creates-confusion%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Vulnerability disclosure is the reporting of security bugs and flaws in software and hardware products. Disclosure is usually made directly to the vendor or creator of the flawed product and the exact nature of the problem is typically not disclosed<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-inconsistent-policies-for-vulnerability-disclosures-creates-confusion\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-11469","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=11469"}],"version-history":[{"count":1,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11469\/revisions"}],"predecessor-version":[{"id":11470,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11469\/revisions\/11470"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=11469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=11469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=11469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}