Reviewing 90 Day Responsible Disclosure Policies in 2022

In the field of responsible disclosure, a policy of 90 days to publicly disclose vulnerabilities has been created by industry. This time period should allow the researcher to disclose the vulnerability to the recipient company, giving them time to push a fix out before the original flaw can be announced.However are we in a time where this time period still works? Some vulnerabilities can be fixed fairly rapidly as we work in cloud environments, while others can be more challenging to fix - such as in OT. We talked to Tenable’s Ivan Belyna and Nick Miles about the evolution of the 90 day policy, and its present and future, and what use advanced disclosure is to security leaders and to the wider industry.  Show ReferencesTales of Zero-Day Disclosure white paper 2020 Podcast with Tenable's Zero-Day Team Follow along for more from Tenable Research:Subscribe to the blogFollow Tenable's Zero Day team on Medium

Om Podcasten

Join members of Tenable Research for a discussion about the latest vulnerabilities, exploits and cyber threats. Analysis, insights and guidance for information security and IT professionals who want to stay in the know.