search menu icon-carat-right cmu-wordmark

The CERT Guide to Coordinated Vulnerability Disclosure

Podcast
Allen Householder and David Warren discuss the CERT Guide to Coordinated Vulnerability Disclosure, which is used by security researchers, software vendors, and other stakeholders in informing others about security vulnerabilities.
Publisher

Software Engineering Institute

Listen

Watch

Abstract

Security vulnerabilities remain a problem for vendors and deployers of software-based systems alike. Vendors play a key role by providing fixes for vulnerabilities, but they have no monopoly on the ability to discover vulnerabilities in their products and services. Knowledge of those vulnerabilities can increase adversarial advantage if deployers are left without recourse to remediate the risks they pose. Coordinated Vulnerability Disclosure (CVD) is the process of gathering information from vulnerability finders, coordinating the sharing of that information between relevant stakeholders, and disclosing the existence of software vulnerabilities and their mitigations to various stakeholders, including the public. The CERT Coordination Center has been coordinating the disclosure of software vulnerabilities since its inception in 1988. In this podcast, Allen Householder and David Warren discuss the CERT Guide to Coordinated Vulnerability Disclosure, which is intended for use by security researchers, software vendors, and other stakeholders in navigating the complexities of informing others about security vulnerabilities. The Guide was recently updated in response to user feedback and has influenced both the U.S. Congress and EU Parliament in their approaches to vulnerability disclosure policy.

About the Speaker

Headshot of Allen Householder

Allen D. Householder

Allen D. Householder is a senior vulnerability researcher in the CERT Division of Carnegie Mellon University's Software Engineering Institute. Householder's research interests include applications of complex systems theory and machine learning to software and system security, fuzzing, and modeling of information sharing and trust among cybersecurity responders.

 

Read more

David Warren

David Warren is an SEI alumni employee.

David Warren is a senior member of the technical staff focused on vulnerability analysis and discovery. Warren reverse engineers systems and tries to move the needle towards security.

Read more