RA-5(11): Public Disclosure Program
Control Family:
Parent Control:
PF v1.0 References:
Baselines:
- Low
- Moderate
- High
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Control is new to this version of the control set.
Control Statement
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Supplemental Guidance
The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.
OT Discussion
For federal organizations, CISA [Binding Operational Directive 20-01](https://cyber.dhs.gov/bod/20-01/) requires individual federal civilian executive branch agencies to develop and publish a vulnerability disclosure policy (VDP) for their internet-accessible systems and services and maintain processes to support their VDP. A VDP may be implemented at the organization level rather than for each individual system. Federal and non-federal organizations could achieve this control by creating and monitoring an email address published on a public-facing website for contacting the organization regarding disclosures.