ISO/IEC 29147
Vulnerability disclosure
Overview
Provides guidelines for how vendors should receive information about potential vulnerabilities in their products or online services, and how they should coordinate with external researchers and other parties.
Applicability
Vulnerability disclosure processes and coordination
Relevance to Cyber Resilience Act (CRA)
Directly addresses CRA vulnerability handling and disclosure requirements
Key Coverage Areas
Standard Sections & Chapters
Vulnerability disclosure policy
Receiving vulnerability reports
Processing vulnerability reports
Coordinating vulnerability remediation
Public disclosure
Related Cyber Resilience Act (CRA) Articles
Article 16: Establishment of a single reporting platform
View Article →Vulnerability disclosure policy and coordination
Implementation Guidance:
Establish vulnerability disclosure policy, reporting mechanism, and coordination process
Mapped Obligations:
- ENISA must establish and maintain a single reporting platform for vulnerability and incident notifications
Quick Information
- Organization
- ISO/IEC
- Category
- Vulnerability Management
- Certification
- Not available