CA/Vulnerability Disclosure: Difference between revisions

Jump to navigation Jump to search
m
Numbering
(Added hyperlinks)
m (Numbering)
Line 107: Line 107:
The following information does not need to be duplicated in the Reportable Vulnerability bug if it can be fully provided in the [https://www.ccadb.org/cas/incident-report public-facing Incident Report]:  
The following information does not need to be duplicated in the Reportable Vulnerability bug if it can be fully provided in the [https://www.ccadb.org/cas/incident-report public-facing Incident Report]:  


# Summarize the steps taken to address the root cause(s) and to strengthen security controls to prevent a similar vulnerability/incident in the future;
3. Summarize the steps taken to address the root cause(s) and to strengthen security controls to prevent a similar vulnerability/incident in the future;
# Detail any other steps being taken to mitigate the effects of the vulnerabilities/incident, including the status of each action, and the date each action will be completed; and
 
# Highlight any collaboration or assistance received from external parties, such as incident response teams, forensics, or law enforcement.
4. Detail any other steps being taken to mitigate the effects of the vulnerabilities/incident, including the status of each action, and the date each action will be completed; and
 
5. Highlight any collaboration or assistance received from external parties, such as incident response teams, forensics, or law enforcement.


==== 5.  CA Remediation Measures ====
==== 5.  CA Remediation Measures ====
Confirmed users
569

edits

Navigation menu