Are You Ready for the New NIST Control Around Public Disclosure Programs?
ID: 6630eba6-64cd-5312-95a8-352d9cda5ddb
STIX ID: report--6630eba6-64cd-5312-95a8-352d9cda5ddb
Feed Name: HackerOne Blog
This article explains NIST SP 800-53 Rev 5 control RA-5(11), which requires SaaS vendors to establish a publicly discoverable vulnerability reporting channel, and provides practical guidance for building and evaluating vulnerability disclosure policies (VDPs) for FedRAMP compliance. It details recommended VDP elements—promise, scope, safe harbor, process, and preferences—highlights assessment questions auditors will ask (discoverability, consistency, scope, finding types, safe harbor, and ease of contact), and describes HackerOne and Schellman & Company perspectives and service offerings to help organizations implement compliant VDPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
