What must the public vulnerability disclosure policy include?
A security mailbox alone is not enough. Provision 5.2-1 says the manufacturer shall make the policy publicly available and include contact information for reporting issues, a timeline for initial acknowledgement of receipt, and timelines for status updates to the reporter until resolution.
For visitors, buyers, researchers, and assessors, the policy should make the reporting path visible without requiring private documentation. TS 103 701 turns that into both a conceptual and functional assessment: the test laboratory checks the publication route described in IXIT 2-UserInfo and verifies that the policy is publicly accessible.
- Publish a clear external location for the , such as a security page or support path that remains reachable without authentication.
- Include contact information that lets security researchers and other reporters submit potential vulnerabilities.
- State an acknowledgement timeline and status-update timelines. ETSI allows different ways to express time values, but the policy still has to tell reporters what to expect.
- Keep product documentation, app help, or support pages aligned with the public policy location if those channels direct users to report security issues.
Primary ETSI requirement for publishing a vulnerability disclosure policy with reporting contact information and acknowledgement/status-update timelines.
Assessment method for checking that the vulnerability disclosure policy publication is available and publicly accessible through IXIT 2-UserInfo.