Are You Ready for the New NIST Control Around Public Disclosure Programs?
hackerone.com | blog | #compliance | #vdp | #vulnerability-disclosure | #policy | #fedramp | #saas | #nist
Summary
NIST 800-53 Rev 5 adds control RA-5(11), requiring SaaS vendors to run a publicly discoverable vulnerability reporting channel. The article outlines VDP options and FedRAMP compliance implications.
- Published
- Collected
Skip to content