HomeSecurityUnited Kingdom: Companies must have a clear vulnerability reporting policy

United Kingdom: Companies must have a clear vulnerability reporting policy

The National ​​Security Cyber (NCSC) in the UK has released a guide aimed at helping companies implement or improve vulnerability reporting policies on systems .

vulnerabilities

The guide is called “The Vulnerability Disclosure Toolkit” and emphasizes that all organizations, regardless of size, should adopt the approach of responsible bug reporting, which means that anyone who finds a vulnerability will be able to report it easily and there will be an immediate response from the company.

Bug reporting policy will become law

The process of vulnerability disclosure is very important, as most attacks are the result of one or more vulnerabilities. Researchers are constantly discovering new bugs and trying to fix them.

Reporting problems can be particularly difficult, because often, those who find vulnerabilities do not know where to turn and to whom to report them.

“Vulnerabilities are being identified all the time and people want to be able to report them directly to the responsible organization,” says the UK’s NCSC.

Companies that want to reduce the number of vulnerabilities in systems need to provide more secure products and services. In this way, they can reduce the chances of falling victim to a cyberattack.

“Having a specific vulnerability reporting process shows that your organization takes security. By providing a clear process, organizations can get information quickly so that the vulnerability can be addressed and the risk of a breach reduced. This process provides a way to report and a defined policy for how the organization will respond,” the NCSC said.

companies

The document published by the NCSC is not a “rule book” for easier vulnerability disclosure. It essentially provides basic information for implementing such a policy or for improving it, in case some companies already implement it.

As we read on BleepingComputer, the document is divided into three main sections that describe how vulnerabilities can be easily disclosed by third parties.

The NCSC recommends creating and providing a dedicated “contact” (email address or secure web form) that can be easily found by anyone who wants to report vulnerabilities. This can be easily done with the security.txt standard, a plain text file.

This file can include contact information for the security and vulnerability disclosure policy. It can also include a public key, if encrypted communication is required, and preferred languages. The NCSC provides a security.txt file as an example.

Responding promptly to a vulnerability report is essential. The company should immediately contact the person who finds the vulnerability, even thanking them.

The NCSC recommends that companies avoid forcing the “vulnerability researcher” to sign a non-disclosure agreement “as the individual is simply trying to ensure that the vulnerability is fixed.”

The company's immediate response and informing the researcher about the progress of the correction shows transparency and appreciation of his efforts.

The release of “The Vulnerability Disclosure Toolkit” is the prelude to the integration of the vulnerability reporting process into the UK legislative framework.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS