- Supports the PSTI vulnerability-disclosure workflow requirement to publish reporting information and expected acknowledgement and status-update timescales.
"publishing information on how to report security issues"
Vulnerability Disclosure Workflow decisions under UK PSTI Product Security should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.
Use this guide to turn official requirements into scope, evidence, owner, and review decisions. This guidance is practical, source-linked, and should be validated against current legal and policy requirements before implementation.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page helps you determine which UK PSTI Product Security duties apply, who owns each action, required evidence, and the review path for escalation decisions.
Treat the workflow as an intake and response process: receive the security report, record the product and reporter details, confirm the report can be acted on, track the acknowledgement and status-update timings promised to the reporter, assess whether the issue is in scope, and escalate any compliance failure through the business and OPSS notification process when needed.
A useful template captures the intake details, the promised acknowledgement and status-update timings, the scope decision, the remediation owner, any escalation path, and the evidence needed to show that the report was handled in line with the published process.
Review the workflow after firmware changes, supplier changes, product bundling changes, UK market placement changes, vulnerability reports, OPSS notices, or support-period updates.
Use this UK PSTI Product Security guide to turn Vulnerability Disclosure Workflow into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.
Turn Vulnerability Disclosure Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"publishing information on how to report security issues"
"The government has been working with the tech industry to better secure consumer connectable products for several years"
"publishing information on how to report security issues"
"security requirements for relevant connectable products"
"The manufacturer must provide information on how to report to them security issues about their product."