Dictionary Home » Webster's New World Hacker Dictionary » Disclosure Policy of CERT/CC

Disclosure Policy of CERT/CC

Disclosure Policy of CERT/CC definition - hacker
As of October 2000, the CERT Coordination Center (CERT/CC) brought in a new policy regarding the disclosure to the public of vulnerability information. According to the CERT/CC, vulnerabilities reported to them will be revealed to the public 45 days after the initial report is made, regardless of the availability of patches. Extenuating circumstances, the new policy states—such as active exploitation, threats of a very serious nature, or situations requiring changes to an established standard—could result in an amended disclosure period.

Because the purpose of the new policy is to balance the publicÂ’s need to be informed with the vendorÂ’s need to respond effectively and efficiently to worms and viruses, CERT/CCÂ’s final decision on when to publish the information will be based on the best interests of the community. According to this policy, vulnerabilities reported to the CERT/CC are transmitted to the affected vendors as soon as possible after the initial report is received; confidentiality of the source is maintained.

See Also: Exploit; Vulnerabilities of Computers; Worm.

Carnegie Mellon University. CERT/CC Vulnerability Disclosure Policy. [Online, 2002.] Carnegie Mellon University CERT Website. http://www.cert.org/kb/vul_ disclosure.html.

Webster's New World Hacker Dictionary Copyright © 2006 by Bernadette Schell and Clemens Martin.
Published by Wiley Publishing, Inc., Indianapolis, Indiana.
Used by arrangement with John Wiley & Sons, Inc.

Comments
Improve this definition.
Do you have more to add? Share your linguistic knowledge or observation.
/Register to save your comments.