Responsible disclosure: A principle that promotes the ethical reporting of security vulnerabilities. Under this principle, when someone discovers a security vulnerability, they should privately notify the relevant entity, providing them adequate time to rectify the issue before disclosing the vulnerability to the public. This practice helps to prevent potential exploitation of the vulnerability by malicious actors, ensuring that corrective measures are put in place to protect users and systems.
Categories: CC D5: Security Operations | CCSP D6: Legal - Risk and Compliance | CISM D4: Incident Management | CISSP D7: Security Operations | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index