What is the vulnerability disclosure workflow under NIST SP 800-218 SSDF?
Publish or otherwise provide a reporting path, preserve the submission, acknowledge it under the organization's policy, and investigate credible reports. Correlate the report with internal testing and public or supplier information, then identify affected products, supported releases, versions, and third-party components.
Analyze each confirmed vulnerability far enough to plan a risk response. Record exploitability, potential impact, relevant deployment conditions, available mitigation, and other criteria used by the organization. Decide whether to remediate, temporarily mitigate, accept, transfer, or otherwise address the risk, and prioritize the work.
When acquirers need to act, provide useful information such as the affected software, how to identify it, available patches or other remediations, configuration changes, and temporary workarounds. Deliver remediations through a trusted mechanism. Then record root cause, look for similar vulnerabilities, and update the SDLC when appropriate.
RV.1.3 recommends a vulnerability-disclosure and remediation policy plus supporting roles, responsibilities, and processes. It does not set a universal acknowledgment, remediation, publication, or embargo deadline; contracts, laws, sector rules, and coordinated-disclosure arrangements may add separate obligations.
- Program owner: maintain the disclosure and remediation policy, reporting instructions, roles, escalation paths, and communication plan.
- Triage owner: preserve the report, assess credibility, coordinate safely with the reporter, and identify affected products, versions, and components.
- Product and security owners: analyze risk, choose and implement the response, test the remediation, and update decision records.
- Communications or product owner: give affected acquirers the information and remediation they need through trusted channels.
- SDLC owner: analyze root causes and similar vulnerabilities, then update tools or practices when the evidence supports a change.
RV.1 covers information gathering, investigation of credible reports, code review or testing, and disclosure-policy operations. RV.2 covers risk analysis, prioritized risk responses, advisories, and trusted remediation delivery. RV.3 covers root causes, similar vulnerabilities, and SDLC updates.