Secure by Design: A Guide for Manufacturers (CISA)
Secure by Design Pledge (May 2024): seven goals – Secure by Design: A Guide for Manufacturers (CISA)

Secure by Design: A Guide for Manufacturers (CISA) PLEDGE-5: Pledge goal 5: Vulnerability disclosure policy

Within a year of signing, publish a VDP that authorises public testing of the manufacturer's products, promises the manufacturer will neither take nor encourage legal action against researchers acting in good faith under it, provides a clear reporting channel and allows public disclosure in line with coordinated vulnerability disclosure practice and international standards. Progress may be shown by the published policy, a machine-readable description such as security.txt, and posts on lessons learned.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Secure by Design Pledge (May 2024): seven goals – Secure by Design: A Guide for Manufacturers (CISA)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.