CA/Vulnerability Disclosure: Difference between revisions

m
m (→‎Types of Vulnerabilities/Incidents to be disclosed: Rephrased to Security Incidents based on comment received)
Line 41: Line 41:
* Confirmed advanced persistent threats that attempt to compromise the CA's infrastructure, systems, or the reliability or validity of certificates.  
* Confirmed advanced persistent threats that attempt to compromise the CA's infrastructure, systems, or the reliability or validity of certificates.  


'''The following would not ordinarily be considered Reportable Vulnerabilities:'''
'''The following are NOT ordinarily considered to be Reportable Vulnerabilities:'''


* Minor security policy violations:  Non-malicious violations of internal security policies by employees that are promptly addressed and do not result in unauthorized access or compromise of critical systems or infrastructure.
* Minor security policy violations:  Non-malicious violations of internal security policies by employees that are promptly addressed and do not result in unauthorized access or compromise of critical systems or infrastructure.
Confirmed users
570

edits