1) initial
acknowledgement
of receipt; and
2) status updates
until the resolution of
the reported issues.
5.3: Keep
software
updated
website and user guidance
documents; Use of a web form;
Use of a vulnerability coordination
and bug bounty platform (e.g.
HackerOne).
5.2-2:
Disclosed
vulnerabilities
should be acted on in a
timely manner.
5.2-3:
Manufacturers
should
continually monitor for,
identify and rectify security
vulnerabilities
within
products and services they
sell,
produce,
have
produced and services they
operate during the defined
support period.
R
R
R
R
R
R
R
R
5.3-1:
All software components in
consumer IoT devices
should
be
securely
updateable.
5.3-2:
When the device is not a
R
R
R
R
MC
(5)
MC
(5)
MC
(5)
MC
(5)
2. Procedures around the initial
acknowledgement of receipt.
3. Procedures around the status
updates of the vulnerability until it
is resolved.
4. [For
5.2-2]
The
internal
guidelines/policies describing the
expected time required for
resolving vulnerabilities.
5. [For 5.2-3] Supporting evidence
that describe internal processes
for
continuous
monitoring,
identification, and rectification of
security vulnerabilities.
Supporting evidence shall list all the
software components in the device and
describe how each of them can be
securely updateable.
Supporting evidence shall describe the
various update mechanisms supported
CLS Publication #2 | Page 26 of 49