02 — Capability · BC-1270.40
Vulnerability & Disclosure Handling
Receive vulnerability reports from researchers, customers and scanners, fix them within committed timelines, and tell affected customers what happened and what to do.
- Vulnerability Management
- Bug Bounty
- Security Advisories
In scope
- Coordinated disclosure program and researcher intake
- Triage, severity rating and remediation timelines
- Security advisories and customer notification
- Software supply chain and dependency vulnerability tracking
Out of scope
- Enterprise vulnerability scanning of internal systems (see BC-760)
Decomposes into · 4
- BC-1270.40.10Disclosure Program & IntakeRun a clear, safe way for outsiders to report vulnerabilities, with rewards where it makes sense and a response within days.
- BC-1270.40.20Triage & RemediationRate each finding, assign it an owner and fix it within the timeline the severity demands, tracking misses as debt.
- BC-1270.40.30Security Advisories & NotificationPublish advisories and notify affected customers with enough detail to act and no more than necessary to exploit.
- BC-1270.40.40Supply Chain Vulnerability TrackingKnow every third-party component the product ships and respond when one of them is found vulnerable.