{"id":17579,"date":"2022-08-16T16:38:42","date_gmt":"2022-08-16T14:38:42","guid":{"rendered":"https:\/\/duthler.nl\/services\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/"},"modified":"2026-02-05T10:22:44","modified_gmt":"2026-02-05T09:22:44","slug":"coordinated-vulnerability-disclosure-cvd","status":"publish","type":"page","link":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/","title":{"rendered":"Coordinated Vulnerability Disclosure (CVD)"},"content":{"rendered":"\n<div class=\"wp-block-cover alignfull\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-nv-light-bg-background-color has-background-dim-100 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-left has-neve-text-color-color has-text-color has-large-font-size\">Need help organizing your Coordinated Vulnerability Disclosure (CVD) policy?<\/h2>\n\n\n\n<p class=\"has-neve-text-color-color has-text-color\">Cyber threats arise from vulnerabilities in the ICT infrastructure, applications and\/or in the organization of business activities. They can undermine the effective protection of company activities and of company and personal data. Ultimately, these vulnerabilities can threaten the continuity of business operations and even shut down a company. The causes of the vulnerabilities can lie in, for example, the complexity of the digital systems, the lack of \u201csecurity by design\u201d, incorrect implementation and\/or insufficient testing. The causes may also lie with chain partners who supply products, applications and services to the company. <\/p>\n\n\n\n<div class=\"wp-block-columns has-neve-text-color-color has-text-color is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><strong>Sharing research results<\/strong><\/p>\n\n\n\n<p>A vulnerability can be noticed by an unknown researcher. If this researcher is in good faith, he will be happy to share the research results with the company. It is important to handle the researcher\/reporter and the report correctly to prevent the information from falling into unwanted hands before the company can resolve the vulnerability. <\/p>\n\n\n\n<p>With a Coordinated Vulnerability Disclosure (CVD) policy, a company can arrange that vulnerabilities identified outside the company are handled in a controlled manner (under your direction). The policy sets out frameworks for documenting and analyzing these vulnerabilities and quickly resolving them by taking appropriate measures. <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>As a result, the consequences for business operations are limited. On the website, the company states in a CVD Policy how vulnerabilities can be reported and under what conditions.<\/p>\n\n\n\n<p><strong>Embedding in your own organization<\/strong><\/p>\n\n\n\n<p>Before a company can go public with a CVD Statement, CVD must first be set up in its own organization. After all, promising a researcher to work according to agreements and then not fulfilling them can have the opposite effect, causing the researcher to take other paths to exploit the vulnerability.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n\n<div class=\"wp-block-cover alignfull\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-nv-site-bg-background-color has-background-dim-100 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-left has-neve-text-color-color has-text-color has-large-font-size\">What is our approach?<\/h2>\n\n\n\n<p class=\"has-neve-text-color-color has-text-color\">A company has to make choices about how it wants to organize CVD. If there is little knowledge and\/or capacity available, it can be decided to outsource the process. You can also opt for partial outsourcing and supplementing your own knowledge through training.<\/p>\n\n\n\n<div class=\"wp-block-columns has-neve-text-color-color has-text-color is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\">Support<\/h3>\n\n\n\n<p>We can support you with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Supporting the preparation of a business case to explore possibilities and make informed decisions;<\/li>\n\n\n\n<li>Drawing up an internal CVD policy and an external CVD policy;<\/li>\n\n\n\n<li>Developing roles, tasks and powers;<\/li>\n\n\n\n<li>Drawing up a procedure to handle a report properly and in a timely manner, including documentation and reporting;<\/li>\n\n\n\n<li>Making agreements with experts to be available on demand when dealing with a vulnerability such as technical IT knowledge and legal knowledge;<\/li>\n\n\n\n<li>Training employees to perform roles; and<\/li>\n\n\n\n<li>Maintaining contact with the reporter.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\">Recognizing vulnerabilities<\/h3>\n\n\n\n<p>Most companies use cloud service providers to support business processes with IT products and services that effectively organize business operations. Most cloud services, the company offers a range of professional controls targeting, for example, the NIST CyberSecurity Framework Core, April, 2018.<\/p>\n\n\n\n<p>MYOBI Trust Network adds to this <a href=\"https:\/\/www.nist.gov\/cyberframework\/framework\" target=\"_blank\" rel=\"noreferrer noopener\">NIST framework<\/a> the management of vulnerabilities in company IT products and services that have been identified by researchers; a Coordinated Vulnerability Disclosure.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\">Trust network helps users<\/h3>\n\n\n\n<p>Most companies use cloud service providers to support business processes with IT products and services that effectively organize business operations. Most cloud services, the company offers a range of professional controls targeting, for example, the <a href=\"https:\/\/www.nist.gov\/cyberframework\/framework\" target=\"_blank\" rel=\"noreferrer noopener\">NIST CyberSecurity Framework Core, April, 2018<\/a>.<\/p>\n\n\n\n<p>MYOBI Trust Network adds to this NIST framework the management of vulnerabilities in company IT products and services identified by researchers; a Coordinated Vulnerability Disclosure. <\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n\n<div class=\"wp-block-cover alignfull\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-nv-light-bg-background-color has-background-dim-100 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-text-align-left has-neve-text-color-color has-text-color has-large-font-size\">Do you have any questions or would you like to make an appointment? <\/h2>\n\n\n\n<p class=\"has-neve-text-color-color has-text-color\">Do you have questions about organizing, implementing or expanding your accountability? Our service owner, Andr\u00e9 Biesheuvel or one of his colleagues, will be happy to discuss your specific case.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-primary\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/duthler.nl\/en\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">Contact us<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":8,"featured_media":0,"parent":17568,"menu_order":3,"comment_status":"closed","ping_status":"closed","template":"","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"on","neve_meta_content_width":100,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"on","neve_meta_reading_time":"","_themeisle_gutenberg_block_has_review":false,"footnotes":""},"class_list":["post-17579","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Coordinated Vulnerability Disclosure (CVD) - Duthler Associates<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coordinated Vulnerability Disclosure (CVD) - Duthler Associates\" \/>\n<meta property=\"og:url\" content=\"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/\" \/>\n<meta property=\"og:site_name\" content=\"Duthler Associates\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-05T09:22:44+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Duthler_NL\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/coordinated-vulnerability-disclosure-cvd\\\/\",\"url\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/coordinated-vulnerability-disclosure-cvd\\\/\",\"name\":\"Coordinated Vulnerability Disclosure (CVD) - Duthler Associates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#website\"},\"datePublished\":\"2022-08-16T14:38:42+00:00\",\"dateModified\":\"2026-02-05T09:22:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/coordinated-vulnerability-disclosure-cvd\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/coordinated-vulnerability-disclosure-cvd\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/coordinated-vulnerability-disclosure-cvd\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/duthler.nl\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Services\",\"item\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Protecting personal data\",\"item\":\"https:\\\/\\\/duthler.nl\\\/en\\\/diensten\\\/beschermen-van-persoonsgegevens\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Organizing accountability\",\"item\":\"https:\\\/\\\/duthler.nl\\\/en\\\/services\\\/protecting-personal-data\\\/organising-accountability\\\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"Coordinated Vulnerability Disclosure (CVD)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/duthler.nl\\\/en\\\/\",\"name\":\"Duthler Associates\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/duthler.nl\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#organization\",\"name\":\"Duthler Associates\",\"url\":\"https:\\\/\\\/duthler.nl\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/duthler.nl\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/0.png\",\"contentUrl\":\"https:\\\/\\\/duthler.nl\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/0.png\",\"width\":400,\"height\":400,\"caption\":\"Duthler Associates\"},\"image\":{\"@id\":\"https:\\\/\\\/duthler.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Duthler_NL\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/duthler-associates\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/duthlerassociates\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Coordinated Vulnerability Disclosure (CVD) - Duthler Associates","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/","og_locale":"en_US","og_type":"article","og_title":"Coordinated Vulnerability Disclosure (CVD) - Duthler Associates","og_url":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/","og_site_name":"Duthler Associates","article_modified_time":"2026-02-05T09:22:44+00:00","twitter_card":"summary_large_image","twitter_site":"@Duthler_NL","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/","url":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/","name":"Coordinated Vulnerability Disclosure (CVD) - Duthler Associates","isPartOf":{"@id":"https:\/\/duthler.nl\/en\/#website"},"datePublished":"2022-08-16T14:38:42+00:00","dateModified":"2026-02-05T09:22:44+00:00","breadcrumb":{"@id":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/coordinated-vulnerability-disclosure-cvd\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/duthler.nl\/en\/"},{"@type":"ListItem","position":2,"name":"Services","item":"https:\/\/duthler.nl\/en\/services\/"},{"@type":"ListItem","position":3,"name":"Protecting personal data","item":"https:\/\/duthler.nl\/en\/diensten\/beschermen-van-persoonsgegevens\/"},{"@type":"ListItem","position":4,"name":"Organizing accountability","item":"https:\/\/duthler.nl\/en\/services\/protecting-personal-data\/organising-accountability\/"},{"@type":"ListItem","position":5,"name":"Coordinated Vulnerability Disclosure (CVD)"}]},{"@type":"WebSite","@id":"https:\/\/duthler.nl\/en\/#website","url":"https:\/\/duthler.nl\/en\/","name":"Duthler Associates","description":"","publisher":{"@id":"https:\/\/duthler.nl\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/duthler.nl\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/duthler.nl\/en\/#organization","name":"Duthler Associates","url":"https:\/\/duthler.nl\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/duthler.nl\/en\/#\/schema\/logo\/image\/","url":"https:\/\/duthler.nl\/wp-content\/uploads\/2019\/06\/0.png","contentUrl":"https:\/\/duthler.nl\/wp-content\/uploads\/2019\/06\/0.png","width":400,"height":400,"caption":"Duthler Associates"},"image":{"@id":"https:\/\/duthler.nl\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Duthler_NL","https:\/\/www.linkedin.com\/company\/duthler-associates","https:\/\/www.youtube.com\/user\/duthlerassociates"]}]}},"_links":{"self":[{"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/pages\/17579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/comments?post=17579"}],"version-history":[{"count":1,"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/pages\/17579\/revisions"}],"predecessor-version":[{"id":23051,"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/pages\/17579\/revisions\/23051"}],"up":[{"embeddable":true,"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/pages\/17568"}],"wp:attachment":[{"href":"https:\/\/duthler.nl\/en\/wp-json\/wp\/v2\/media?parent=17579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}