RA-05.11 ยท Public Disclosure Program

Control Description

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Assurance
Enhancement
Control Statement
The control requirements

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Supplemental Guidance

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.