Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


  • Publishing vulnerability information. Providing high-quality, timely, targeted, automated dissemination of vulnerability information enables defenders to make informed decisions and take action quickly.
  • Encouraging the adoption and widespread use of exploit mitigation techniques on all platforms.
  • Reducing days of risk. Selecting reasonable disclosure deadlines is one way of achieving the goal of minimizing the time between a vulnerability's discovery and the remediation of its last deployed instance [4]. Another way is to shorten the time between vulnerability disclosure and patch deployment by automating patch distribution using secure update mechanisms that make use of cryptographically signed updates or other technologies.

  • Releasing high-quality patches. Increasing defenders' trust that patches won't break things or have undesirable side effects reduces lag in patch deployment by reducing the defenders' testing burden.
  • When possible, automated patch deployment can improve patch deployment rates too.


    < 2. Principles of Coordinated Vulnerability Disclosure | 2.2. Presume Benevolence >


  1. Harm Reduction Coalition, "Principles of Harm Reduction," [Online]. Available:
  2. Harm Reduction Coalition, "What is harm reduction?" [Online]. Available:
  3. A. Householder, "Systemic Vulnerabilities: An Allegorical Tale of SteampunkVulnerability to Aero-Physical Threats," August 2015. [Online]. Available:
  4. A. Arora, A. Nandkumar and R. Telang, "Does information security attack frequency increase with vulnerability disclosure? An empirical analysis," Information Systems Frontiers, vol. 8, no. 5, pp. 350-362, 2006.