Standard Tekniska rapporter · SS-ISO/IEC TR 5895:2025

Cybersäkerhet – Samordnad sårbarhetsrapportering och hantering med flera parter (ISO/IEC TR 5895:2022, IDT)

Status: Gällande

Köp denna standard

Standard Tekniska rapporter · SS-ISO/IEC TR 5895:2025

Cybersäkerhet – Samordnad sårbarhetsrapportering och hantering med flera parter (ISO/IEC TR 5895:2022, IDT)
Prenumerera på standarden - Läs mer Dölj
Pris: 920 SEK
standard ikon pdf

PDF

Pris: 920 SEK
standard ikon

Papper

Pris: 1 472 SEK
standard ikon pdf + standard ikon

PDF + papper

Fler alternativ Färre alternativ
Provläs denna standard
Omfattning
This document clarifies and increases the application and implementation of ISO/IEC 30111 and ISO/IEC 29147 in multi-party coordinated vulnerability disclosure (MPCVD) settings, including the evolving commonly adopted practices in this area, by articulating:


—    The MPCVD life cycle and application of coordinated vulnerability disclosure (CVD) stages (preparation, receipt, verification, remediation[1] development, release, post-release) in MPCVD settings.


—    Stakeholders involved in MPCVD include users, vendors (coordinating, mitigating, and dependent vendors), reporters, and non-vendor coordinators (entities defined in ISO/IEC 29147 and ISO/IEC 30111).


—    The exchange of information between stakeholders during the vulnerability handling and disclosure process in a MPCVD settings.


Clarifying the application of ISO/IEC 30111 and ISO/IEC 29147 in MPCVD settings illustrates the benefits of vulnerability disclosure processes.


 


[1] Remediation is a defined term used in ISO/IEC 30111 and ISO/IEC 29147. This document uses the term "remediation" and verb “remediate” in the context of this definition.

Ämnesområden

IT-säkerhet (35.030)


Köp denna standard

Standard Tekniska rapporter · SS-ISO/IEC TR 5895:2025

Cybersäkerhet – Samordnad sårbarhetsrapportering och hantering med flera parter (ISO/IEC TR 5895:2022, IDT)
Prenumerera på standarden - Läs mer Dölj
Pris: 920 SEK
standard ikon pdf

PDF

Pris: 920 SEK
standard ikon

Papper

Pris: 1 472 SEK
standard ikon pdf + standard ikon

PDF + papper

Fler alternativ Färre alternativ

Produktinformation

Språk: Engelska

Framtagen av: Kravställning och verifiering, SIS/TK 318/AG 31

Internationell titel: Cybersecurity — Multi-party coordinated vulnerability disclosure and handling (ISO/IEC TR 5895:2022, IDT)

Artikelnummer: STD-82098057

Utgåva: 1

Fastställd: 2025-08-25

Antal sidor: 22