Thursday, December 10, 2020
  • VMRay Closes $25 Million Series B
  • Goodbye to Flash – if you’re still running it, uninstall Flash Player now
  • Smart DNS: Delivering the Best Subscriber Experience
  • New Microsoft Spear-Phishing Attack Uses Exact Domain Spoofing Tactic
  • 6 ways to use analytics to deliver an exceptional end-user experience: Part 3

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Bloggers Network
    • Latest Posts
    • Contributors
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming
    • On-Demand
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
  • Library
  • Related Sites
    • MediaOps Inc.
    • DevOps.com
    • Container Journal
    • Digital Anarchist
    • SweetCode.io
  • Media Kit

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Security Bloggers Network » Tripwire Survey: Most RSAC Attendees Favor Shorter Vulnerability Disclosure Timelines

Tripwire Survey: Most RSAC Attendees Favor Shorter Vulnerability Disclosure Timelines

by Ray Lapena on May 8, 2018

With continued debate around responsible disclosure and increased attention around security research techniques, Tripwire wanted to get a pulse on what the community considers responsible practices today. In surveying 147 attendees at the RSA Conference in San Francisco a couple weeks ago, we found out a number of interesting perspectives.

Most respondents favored shorter timelines in disclosing vulnerabilities publicly. When asked what’s a reasonable amount of time for allowing a vendor to fix a vulnerability before full public disclosure, 32 percent selected the shortest option of 60 days, followed by 25 percent who said public disclosure does not need to wait on a vendor fix.

Opinions were split on whether people should be allowed to test security constraints of a company’s products/services without upfront approval from that company, with 50 percent believing they should not be allowed and 49 percent saying they should be allowed.

This has been a point of debate recently around new cybersecurity legislation in Georgia, which would affect responsible security researchers’ abilities to do things in the public interest.

As Tripwire security researcher Craig Young has said in response to the proposed legislation:

Security researchers are the first defenders against data breaches. Ethical hackers find vulnerabilities in systems and expose them to product vendors so they can be patched before they are exploited maliciously. Finding and exposing these vulnerabilities is not a criminal act, it is done with the intent of making the products safer for consumer use.

Eighty-four percent of the survey participants did feel that more legislation is needed to protect people/organizations from malicious hackers, though many felt lawmakers need guidance – for 35 percent, it was “Yes, but in partnership with infosec experts.”

The survey also explored participants’ own organizations’ experiences in receiving vulnerability reports. Thirty-sixpercent said that their organization has (Read more...)

*** This is a Security Bloggers Network syndicated blog from The State of Security authored by Ray Lapena. Read the original post at: https://www.tripwire.com/state-of-security/security-data-protection/cyber-security/tripwire-survey-most-rsac-attendees-favor-shorter-vulnerability-disclosure-timelines/

May 8, 2018May 8, 2018 Ray Lapena Cyber Security, Cybersecurity, rsa, VERT
  • ← Addressing the Cybersecurity Skills Shortage with Automation
  • Enterprises Slack at Security Patching at Their Own Peril →

TechStrong TV – Live

Watch latest episodes and shows
Featured Blog

Eric Kedrosky

The Future of Multi-Cloud Security: A Look Ahead at Intelligent Cloud Security Posture Management Solutions

Michael Clark

Prevent Catastrophic Data Loss in the Cloud

Rich Gardner

CISO Roundtable: What We’ve Heard, and What We’re Looking Forward To

Subscribe to our Newsletters

Get breaking news, free eBooks and upcoming events delivered to your inbox.
  • View Security Boulevard Privacy Policy

Most Read on the Boulevard

Tips From a Hacker to Keep Smartphones Safe
Verizon Report Finds Cyber Espionage Attacks Aimed Mostly at Endpoints
Kazakhstan Spies on its People via Man-in-the-Middle Attack, Again
Targeted Cyberattacks Require Targeted Security Awareness Training
One Step Ahead: Using Threat Hunting to Anticipate the Unknown
Why You Need to Have a Risk Register to Keep Track of Cybersecurity Risks
Phishing Attacks on Your Brand are Unrelenting, AI is the Only Way to Fight Back
The Top 19 Internet of Things(IoT) Security Solutions
DEF CON 28 Safe Mode Aerospace Village – Allan Tart’s & Fabian Landis’ ‘Low Cost VHF Receiver’
Add Security Events to Your Monitoring Tools

Upcoming Webinars

Thu 10

Data Security for Contact Centers Leveraging Cloud Technologies

December 10 @ 3:00 pm - 4:00 pm
Mon 14

Issues and Answers in Cloud Security

December 14 @ 1:00 pm - 2:00 pm
Tue 15

3 Things to Get Right for Successful DevSecOps

December 15 @ 3:00 pm - 4:00 pm
Wed 16

Unsolved Problems in Open Source Security

December 16 @ 11:00 am - 12:00 pm
Wed 16

Securing Medical Apps in the Age of COVID-19: How to Close Security Gaps and Meet Accelerated Demand

December 16 @ 1:00 pm - 2:00 pm
Wed 16

Deliver your App Anywhere … Publicly or Privately

December 16 @ 3:00 pm - 4:00 pm
Thu 17

Secure Your Peace of Mind and Your Mobile App While Giving Developers Back Their Happy Coding Time

December 17 @ 11:00 am - 12:00 pm
Thu 17

Solving Kubernetes Security Challenges Using Red Hat OpenShift and Sysdig

December 17 @ 1:00 pm - 2:00 pm
Thu 17

Securing JavaScript/Go Code with Insights and Analytics

December 17 @ 3:00 pm - 4:00 pm
Jan 12

Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport

January 12, 2021 @ 3:00 pm - 4:00 pm

More Webinars

Download Free eBook

Managing the AppSec Toolstack

Recent Security Boulevard Chats

  • Cloud, DevSecOps and Network Security, All Together?
  • Security-as-Code with Tim Jefferson, Barracuda Networks
  • ASRTM with Rohit Sethi, Security Compass
  • Deception: Art or Science, Ofer Israeli, Illusive Networks
  • Tips to Secure IoT and Connected Systems w/ DigiCert

Industry Spotlight

Why Next-Gen Firewalls Miss the Mark for Today’s Remote Workforce
Cybersecurity Industry Spotlight Network Security Security Boulevard (Original) 

Why Next-Gen Firewalls Miss the Mark for Today’s Remote Workforce

December 10, 2020 Mike Riemer | 8 hours ago 0
Pandemic Waves Underscore Vulnerabilities in Cloud File Systems
Cloud Security Cybersecurity Industry Spotlight Security Boulevard (Original) 

Pandemic Waves Underscore Vulnerabilities in Cloud File Systems

December 9, 2020 Edward M.L. Peters | Yesterday 0
One Step Ahead: Using Threat Hunting to Anticipate the Unknown
Cybersecurity Industry Spotlight Security Boulevard (Original) Threat Intelligence 

One Step Ahead: Using Threat Hunting to Anticipate the Unknown

December 8, 2020 Paul German | 2 days ago 0

Top Stories

Kazakhstan Spies on its People via Man-in-the-Middle Attack, Again
Application Security Cloud Security Cyberlaw Cybersecurity Data Security Featured Governance, Risk & Compliance Network Security News Security Awareness Security Boulevard (Original) Spotlight 

Kazakhstan Spies on its People via Man-in-the-Middle Attack, Again

December 7, 2020 Richi Jennings | 2 days ago 0
Verizon Report Finds Cyber Espionage Attacks Aimed Mostly at Endpoints
Cybersecurity Data Security Featured Network Security News Security Boulevard (Original) Spotlight 

Verizon Report Finds Cyber Espionage Attacks Aimed Mostly at Endpoints

December 7, 2020 Michael Vizard | 2 days ago 0
Brazil Govt’s Huge Leak: Health Data of 243M
Application Security Cloud Security Cyberlaw Cybersecurity Data Security Featured News Security Boulevard (Original) Spotlight Threats & Breaches Vulnerabilities 

Brazil Govt’s Huge Leak: Health Data of 243M

December 4, 2020 Richi Jennings | Dec 04 0

Security Humor

Via  the amusing regulatory humor of   Daniel Stori   at   turnoff.us   (from the Archive, originally published in August of 2017)

Daniel Stori’s ‘AI Regulation’

Join the Community

  • Add your blog to Security Bloggers Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: info@securityboulevard.com

Useful Links

  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • Privacy Policy
  • DMCA Compliance Statement

Other Mediaops Sites

  • Container Journal
  • DevOps.com
  • DevOps Connect
  • DevOps Institute
Copyright © 2020 MediaOps Inc. All rights reserved.
Our website uses cookies. By continuing to browse the website you are agreeing to our use of cookies. For more information on how we use cookies and how you can disable them, please read our Privacy Policy.