id: "RA-05(11)" title: "Public Disclosure Program" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.11" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True
Statement
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Guidance
The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.
Assessment Objective
a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.
Risk assessment policy
procedures addressing vulnerability scanning
risk assessment
vulnerability scanning tools and techniques documentation
vulnerability scanning results
vulnerability management records
audit records
public reporting channel
system security plan
other relevant documents or records
Organizational personnel with vulnerability scanning responsibilities
organizational personnel with vulnerability scan analysis responsibilities
organizational personnel with security responsibilities
Organizational processes for vulnerability scanning
mechanisms/tools supporting and/or implementing vulnerability scanning
mechanisms implementing the public reporting of vulnerabilities