The "Equities Process" governs how to handle publicizing security issues. Normally, flaws and vulnerabilities are not announced until after they are fixed. The government will only withhold a bug if there was an “overriding intelligence reason,” and will require sign off from a high-level official.
Estimated reading time: 0 minutes, 23 seconds
U.K. Agency Ups Transparency Protocols to Combat Threats
The National Cyber Security Centre in the U.K. announced a new public disclosure process with respect to “potentially sensitive software flaws.” So reports NBC News.
Latest from Kurt Martin
Most Read
-
-
Jan 30 2020
-
Written by Security Tech Brief Staff
-
-
-
Jan 25 2019
-
Written by Security Tech Brief Staff
-
-
-
May 27 2019
-
Written by Security Tech Brief Staff
-
-
-
Jun 01 2019
-
Written by Security Tech Brief Staff
-