FIRST CSIRT Services Framework and Standards
FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

FIRST CSIRT Services Framework and Standards FIRST-IEP-MPCVD: FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD)

FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD) Guidelines. IEP v2.0: a machine-readable extension of TLP that conveys handling restrictions + sharing permissions in structured form (JSON-LD). IEP CATEGORIES: HANDLING (encryption + authentication required + secure transmission + DESTRUCTION); ACTION (PERMITTED + DENIED + ATTRIBUTION-REQUIRED); SHARING (with whom; for how long; under what classification); LICENSE (terms of use). IEP fields complement TLP for automated CTI routing in STIX/TAXII + open-source threat-intel platforms. MPCVD GUIDELINES: best-practice framework for coordinating vulnerability disclosure when MULTIPLE affected vendors or affected parties exist; structured WORKFLOW including: (a) FIRST coordinator role; (b) VENDOR identification + outreach; (c) DISCLOSURE TIMELINE (typically 90 days + extensions) + per-vendor + global publication date; (d) PATCH availability + customer notification; (e) PUBLIC DISCLOSURE + advisory publication; (f) POST-DISCLOSURE retrospective + lessons learned. Coordinated with ISO/IEC 29147 (Vulnerability Disclosure) + ISO/IEC 30111 (Vulnerability Handling Processes) + the CERT/CC Guide to Coordinated Vulnerability Disclosure.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in FIRST: Related Standards - CVSS, TLP, IEP, MPCVD and PSIRT Services

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.