Security bulletin policy
Security advisories and incident notices for the CyberOptix CTEM Platform are published to Security bulletins, which carries its own RSS feed - separate from Release notes, so subscribing to advisories does not subscribe you to the changelog.
What gets a bulletin
| Type | Published |
|---|---|
| Advisory | A vulnerability in the platform, whether we found it or you did |
| Incident | A security incident affecting the service, after resolution |
A vulnerability fixed before any release shipped it does not get a bulletin - there was nothing for you to be exposed to. One that reached a release does, whether or not we believe it was exploited.
Severity
Bulletins use the same five-level scale as findings in the product, derived from CVSS v3 ranges:
| Severity | Score | Meaning |
|---|---|---|
| Critical | 9.0 - 10.0 | Exploitable remotely with severe impact, little or no precondition |
| High | 7.0 - 8.9 | Serious impact, or severe impact with meaningful preconditions |
| Medium | 4.0 - 6.9 | Limited impact, or significant preconditions |
| Low | 0.1 - 3.9 | Minor impact |
Timing
| Severity | Target |
|---|---|
| Critical | Within 72 hours of a fix being available |
| High | Within 7 days |
| Medium and Low | With the release that fixes them |
Publication is timed to a fix being available, not to it being deployed everywhere, because you may need to act on hosted components yourself. Where a mitigation exists before a fix, we publish the mitigation rather than waiting.
What a bulletin contains
- What the issue is, in terms of what an attacker could do
- Affected versions and components
- Severity and score
- Whether we have evidence of exploitation
- What you need to do, and whether anything is required of you at all
- CVE identifier where one has been assigned
We do not publish exploit details or proof-of-concept code.
Silence
An empty period means no advisories were published in it. It does not mean none were found - it means none reached a release, or none were of a severity that requires one under this policy.
We state that explicitly because a quiet advisory feed is easy to read as an absence of diligence, and because a policy that only describes what happens when something is found tells you nothing about the other case.
Reporting something to us
If you believe you have found a vulnerability in the platform, contact [email protected].
Please give us a reasonable period to investigate and fix before disclosing publicly. We will keep you informed of progress, and we will credit you in the bulletin unless you would rather we did not.
Compliance evidence
If you need evidence of our vulnerability communication process for your own audit, this page plus the bulletin feed is it. Both are public and neither requires a request.