Governance & ComplianceAdvanced Core Compliant Accredited

Vulnerability Disclosure Awareness

Understanding responsible vulnerability disclosure and the management of security vulnerabilities

Vulnerability Disclosure Awareness

Course Overview

This course provides learners with an understanding of vulnerability disclosure and the responsible reporting of security weaknesses in organisational systems and third-party products. Learners will explore the vulnerability disclosure lifecycle, coordinated disclosure principles, patch management obligations and the legal context for security research. The course is suitable for IT security professionals, developers and compliance teams.

Learning Outcomes

  • Understand the purpose of vulnerability disclosure programmes
  • Apply coordinated vulnerability disclosure (CVD) principles
  • Recognise the legal context for security research under UK law
  • Manage the vulnerability disclosure lifecycle from receipt to remediation
  • Understand severity scoring using CVSS
  • Communicate vulnerability disclosures to stakeholders appropriately
  • Support the development of an organisational vulnerability disclosure policy

Course Structure (3 topics, 9 lessons)

Defining Vulnerabilities, Exploits, and Threats
The Coordinated Vulnerability Disclosure (CVD) Process
Roles and Responsibilities in the Disclosure Lifecycle
135 minutes
9 lessons across 3 topics
2.5 CPD hours
Certificate valid 24 months
IT security professionals, developers, compliance teams and those responsible for system security

Full library access during 14-day trial

Topics

Vulnerability DisclosureCVDPatch ManagementBug BountySecurity Research

We value your privacy

We use cookies to analyse site usage and improve your experience. You can accept all cookies, use essential cookies only, or reject non-essential cookies entirely.