Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 9 Next »

Eric Hatleback

Communicating with Specific Parties in VINCE

Communicating with the CERT/CC

To facilitate efficiency during the coordination process, there are multiple ways to communicate with the CERT/CC.

  • Case Discussion: CERT/CC analysts are available within the Case Discussion for every vulnerability coordination case.  Note that any communications posted in the Case Discussion are visible to all participants in the case, including those who may be added to the case in the future.  To communicate with the CERT/CC via the Case Discussion:
    1. Navigate to either "Dashboard" or "Cases".
    2. Click the title of the case for which you want to enter the Case Discussion.
    3. Scroll past any already existing messages and enter your message in the text box at the bottom of the page.
    4. Click "Submit".
  • Private Message: You can send a Private Message directly to the CERT/CC.  Private Messages will be seen only by CERT/CC analysts.  Note that any replies sent from the CERT/CC will be visible to the recipient and any VINCE users associated with the recipient's organization (in the case of vendors).  To send the CERT/CC a Private Message:
    1. Navigate to either "Inbox" or the "Case Discussion" for a particular case.
    2. Click the "Private Message CERT/CC" button.
    3. Create your message and select the most appropriate description for your message from the drop-down menu.
    4. Click "Send".
  • Comment on Vulnerability Reporting Form (VRF): Reporters are able to communicate with the CERT/CC by navigating to {insert specific instructions} and entering a message in the text box at the bottom of the VRF.  Note that this method of communication is available only: 
    1. before the VRF has been converted to a VU# for coordination (at which point the Case Discussion should be used); or
    2. when the reporter wishes to avoid participating in the Case Discussion.

Communicating with Vendors

  • Case Discussion: 

Communicating with Reporters

  • Case Discussion: 

Case discussion (pinned topic, discussion, who is in the room, case history)

VINCEComm ticket comms – what is this called? activity on a ticket, specifically a VRF ticket allows CERT/CC to talk to a reporter who is a VINCE user, called message? activity on case?

inbox – message thread, not a ticket?

PM with CERT/CC - other "send message to CERT/CC" options, inbox > new message

Private thread

For vendors

Receive notification from CERT/CC on new vul report

Providing vendor status

  • No labels