Disclosure Policy
Last Updated: March 27, 2015
Last Updated: March 27, 2015
This document describes the Onapsis Vulnerability Disclosure Policy, which will be used as the general guidelines in the process of disclosing vulnerabilities discovered by the Onapsis Research Labs in the form of a security advisory.
It’s in Onapsis’ best interest to contribute to the continuous improvement of the security level of the enterprise software used by its customers. Therefore, we consider it’s important to establish a clear procedure that should be followed by involved parties in order to minimize risks and provide a holistic solution to security caveats.
Based on years of experience in the industry, we strongly believe that these measures provide the best balance for all the parties involved: vendors, customers and the general community.
General Procedure
Upon the discovery of a new security vulnerability, the following procedure will take place:
1) Onapsis sends an email to the vendor’s public available security email contact, notifying that a new vulnerability has been discovered and requests a PGP/GPG key in order to send the detailed information encrypted.
2) Onapsis sends a Security Vulnerability Submission document to the vendor, which contains the technical information regarding the vulnerability. This document is provided with a reference to this Policy and a preset disclosure date, usually set to 21 days later.
3) Upon successful confirmation of the reception and analysis of the vulnerability, the vendor must provide Onapsis an estimated release date for the solution, which should not be longer than 45 days. Onapsis will post the name of the vulnerability and estimated release date in the “Upcoming Advisories” section of its website.
4) While the solution is being developed, Onapsis will be available to provide further information or specialized assistance to the vendor, in order to better understand the involved risks and contribute in the development of a comprehensive solution. In this process, Onapsis expects the vendor to provide periodic updates about the status of the case.
Eventually, Onapsis will publish the security advisory containing the vulnerability information when any of the following situations takes place: