Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

A process is "a series of actions or steps taken in order to achieve a particular end" ([1)]. Publishing a document is an action. Releasing a fix is an action. And while both of these are common events within the CVD process, they do not define it. Perhaps the simplest description of the CVD process is that it starts with at least one individual becoming aware of a vulnerability in a product. This discovery event immediately divides the world into two sets of people: those who know about the vulnerability, and those who don't. From that point on, those belonging to the set that knows about the vulnerability iterate on two questions:

...