CERTCC / CERT-Guide-to-CVD

Content for the CERT Guide to Coordinated Vulnerability Disclosure
https://certcc.github.io/CERT-Guide-to-CVD/
Other
7 stars 5 forks source link

Bring the guide's usage of "remediation" into line with common usage #6

Closed ahouseholder closed 5 months ago

ahouseholder commented 3 years ago

We currently use "remediation" in the guide to mean both fix and mitigate. For example, see section 4.4 Remediation But other sources use remediation to mean something disjoint from mitigation.

The list above reflects current usage in the guide, but depending on whether or not we use "remediation" to mean 1 or 3, then any of these may need to change.

References to the "remediation = fix (only)" usage include:

  1. https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/853101p.pdf?ver=2020-09-15-143058-347
  2. https://blog.rapid7.com/2020/09/14/vulnerability-remediation-vs-mitigation-whats-the-difference/

This issue is closely related to SSVC#46

ahouseholder commented 5 months ago