id: "RA-05(11)" title: "Public Disclosure Program" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.11" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True


Statement

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Guidance

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.

Assessment Objective

a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.

Risk assessment policy

procedures addressing vulnerability scanning

risk assessment

vulnerability scanning tools and techniques documentation

vulnerability scanning results

vulnerability management records

audit records

public reporting channel

system security plan

other relevant documents or records

Organizational personnel with vulnerability scanning responsibilities

organizational personnel with vulnerability scan analysis responsibilities

organizational personnel with security responsibilities

Organizational processes for vulnerability scanning

mechanisms/tools supporting and/or implementing vulnerability scanning

mechanisms implementing the public reporting of vulnerabilities