FIRST: Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure
Forum of Incident Response and Security Teams (FIRST)
U.S. National Telecommunications and Information Administration (NTIA), Industry Consortium for the Advancement of Security on the Internet (ICASI)
Target countries / regions:
(National) Incident Response Teams; CSIRT; PSIRT; SIRR
Defining a methodology for coordination among the parties affected by a vulnerability, from initial report to releasing information
Aims / objectives:
To meet the need for a more consistent approach to vulnerability disclosure to account for multiple stakeholders
A set of guidelines and norms for vulnerability disclosure that affects multiple parties.
FIRST, via the FIRST secretariat at firstname.lastname@example.org or Kate Gagnon, Director, Forum of Incident Response and Security Teams (FIRST), email@example.com
For more information:
The GFCE inventory is being continuously updated, and the information it contains is either publicly available, or consent for publication was given by the owner. Please contact the portal manager with any additional information or corrections. Whilst every reasonable effort is made to keep the content of this inventory accurate and up to date, no warranty or representation of any kind, express or implied, is made in relation to the accuracy, completeness or adequacy of the information contained in these pages.