NIST 800-53 Rev 5

424 controls available

RA-5(11)lowmoderatehigh

Public Disclosure Program

Risk Assessment

Control Statement

Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.

Discussion

The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability.

Framework
NIST SP 800-53 Rev 5
Family
Risk Assessment
Baselines
low, moderate, high

Related Frameworks

2 paths across 2 frameworks
SCF1 mapping
THR-06Vulnerability Disclosure Program (VDP)
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI1 mapping
CCI-004640
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

12 STIGs reach this control through 31 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Mainframe

2 STIGs
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match

Network Device

2 STIGs

Virtualization / Container

5 STIGs

Endpoint Security Management

1 STIG

Uncategorized

2 STIGs