logo

Are You Ready for the New NIST Control Around Public Disclosure Programs?

ID: 6630eba6-64cd-5312-95a8-352d9cda5ddb

STIX ID: report--6630eba6-64cd-5312-95a8-352d9cda5ddb

Feed Name: HackerOne Blog

Date Published: 2025-06-27

Date Updated: 2026-06-12

...
...

This article explains NIST SP 800-53 Rev 5 control RA-5(11), which requires SaaS vendors to establish a publicly discoverable vulnerability reporting channel, and provides practical guidance for building and evaluating vulnerability disclosure policies (VDPs) for FedRAMP compliance. It details recommended VDP elements—promise, scope, safe harbor, process, and preferences—highlights assessment questions auditors will ask (discoverability, consistency, scope, finding types, safe harbor, and ease of contact), and describes HackerOne and Schellman & Company perspectives and service offerings to help organizations implement compliant VDPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.