AAP Recommendation

X.1219: Functional requirements for a secured process to evaluate technical vulnerabilities

Study Group
17

Study Period
2022-2024

Consent Date
2023-03-03

Approval Date
2023-04-29

Provisional Name
X.arc-ev

Input used for Consent
SG17-TD930-R1-2/PLEN (2023-02)

Status
A

IPR
Site

The vulnerabilities evaluation by crowdsourcing is a good manner for famous online systems to find their technical vulnerabilities, but on the other hand, there are still many problems or challenges such as the shell script uploaded by members of a security team was not deleted after evaluation, resulting in a backdoor in the system. The functional requirements for a secured process to evaluate technical vulnerabilities are recommended in this recommendation. And the functional requirements with corresponded mechanisms would be mainly used to solve the lack of trust in the crowdsourcing manner. It is meaningful to make sure that the vulnerabilities evaluation operated by security teams be reliable, auditable, traceable, and controllable.

AAP Current Status
Step # Action
Start / End
Status Announcement Related documents Comments / Resolution logs