ISS Goes Public With Vulnerability Disclosure Guidelines

Écrit par
Dennis Fisher
Dennis Fisher
Published: Dec 2, 2002
Updated: Feb 2, 2021
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Internet Security Systems Inc. on Monday released to the public the vulnerability disclosure guidelines that its internal X-Force research team uses in identifying flaws and notifying vendors and the public.

The guidelines are fairly standard and include a provision that is becoming more and more common among security vendors that also do vulnerability research. The clause informs vendors that ISS customers who subscribe to the companys X-Force Threat Analysis Service will be told about any new vulnerabilities one business day after ISS notifies the affected vendor. Customers will also get information on any countermeasures that may be available.

Other security vendors have similar policies, under which their paying customers receive early warning of newly discovered flaws. Many vendors also add a check for the vulnerability to their commercial products before the vulnerabilitys existence is public knowledge.

ISS policy also dictates that it will publicly disclose new vulnerabilities 30 days—or perhaps sooner—after the companys initial contact with the vendor, unless other arrangements have been made. And if there is a discussion of a new vulnerability on a public mailing list, the vendor becomes unresponsive or a news article mentions the flaw, then ISS will accelerate its public notification.

“Security research organizations need to implement standards that reflect the publics need to know vital information about vulnerabilities in a timely manner, but that also give ample consideration to software vendors working to remedy issues in their products so that the public is not put at risk without a corrective action available,” said Chris Rouland, director if the X-Force at ISS, based in Atlanta.

ISS is a prominent member of the Organization for Internet Safety, a group of security and software vendors that have banded together to develop a common set of guidelines that can be used for responsible disclosure of vulnerabilities. The group is still working on its guidelines.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.