What is responsible disclosure in cybersecurity?
- A.Publicly announcing a vulnerability immediately after discovering it
- B.Ignoring vulnerabilities found in software
- C.Selling vulnerability information to the highest bidder
- D.Reporting a discovered vulnerability to the vendor privately and giving them time to fix it before public disclosure
Why D is correct
Responsible disclosure (also called coordinated disclosure) means that when a security researcher discovers a vulnerability, they privately report it to the affected vendor and allow a reasonable timeframe (typically 90 days) for the vendor to develop and release a patch before the vulnerability is publicly disclosed.
Know someone studying for Security Fundamentals? Send them this one.