CERTCC / CERT-Guide-to-CVD

Content for the CERT Guide to Coordinated Vulnerability Disclosure
https://certcc.github.io/CERT-Guide-to-CVD/
Other
8 stars 4 forks source link

Embargoes should mention TLP #26

Open ahouseholder opened 2 months ago

ahouseholder commented 2 months ago

Describe the solution you'd like

We already have a discussion of TLP in https://certcc.github.io/CERT-Guide-to-CVD/howto/operation/opsec

A recent conversation with a member of the FIRST TLP SIG brought attention to the idea that we can express an embargo in terms of TLP transitions (e.g., AMBER -> CLEAR) so we should mention that in the embargo discussion and link to the existing TLP words too.