In the course of submitting a security vulnerability to a vendor today, I was referred to the “Organization of Internet Safety” guidelines for reporting (.pdf) security vulnerabilities to vendors.
No worries.
I downloaded it and gave it a read. The part that struck me was that is was released in September 2004. So, I went to check for a possible newer version but, that’s the one. The most recent press release on the site dates from 2004 as well. Has this organization (which, admittedly, I only loosely recall) gone toes up?
Tags: Vulnerability Disclosure, Vulnerabilities, Vendor Disclosure, OIS






























