manage.get.gov/docs/compliance/dist/system-security-plans/ato/ra-5.11.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

1.2 KiB

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

ra-5.11 - [catalog] Public Disclosure Program

Control Statement

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Control guidance

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.

Control assessment-objective

a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.


What is the solution and how is it implemented?

Add control implementation description here for control ra-5.11