Is reporting a security bug different?
Yes, security bugs are treated as a matter of absolute urgency so handling a security vulnerability is different from handling any other kind of bug. The bug report cannot be submitted through the regular channels as the objective is to analyze and fix the bug in secrecy, announcing the existence of the bug and its fix concurrently.
Related Questions
- Are there different certification requirements for managers than for technically oriented information assurance or information security personnel?
- Does EZ-DBR offer different levels of security so employees who enter data cannot see all of my totals and statistics?
- Is reporting a security bug different?