Coordinated Vulnerability Disclosure
A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.
Definition
Coordinated Vulnerability Disclosure (CVD) is the documented process by which a manufacturer accepts vulnerability reports from external researchers, validates and remediates the issues, and publishes advisories - coordinated to give operators time to deploy fixes before attackers exploit them. ISO/IEC 29147:2018 defines the disclosure process and ISO/IEC 30111:2019 defines the internal handling process. FDA, CISA, and ENISA all expect MedTech manufacturers to operate a CVD program.What this means in practice
A working CVD program needs a published security.txt file or vendor security page, a monitored intake address (security@), an SLA-driven triage process, integration with CAPA, and a coordinated-release plan with affected customers and ISACs. Mature MedTech teams also offer Safe Harbor language so good-faith researchers aren't deterred by legal risk.- •No published intake channel - researchers default to public disclosure when they can't reach you.
- •Treating CVD intake as a security-only problem; legal, comms, and clinical-affairs all need playbooks.
- •Publishing advisories without a working VEX/SBOM bridge so operators know which devices need action.
Frequently asked questions
Cross-references
Used by
Things that build on this term.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAn industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
4 sources- 1
ISO/IEC 29147:2018 - Vulnerability disclosureVerifiedISO/IECiso.org
- 2
ISO/IEC 30111:2019 - Vulnerability handling processesVerifiedISO/IECiso.org
- 3
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 4
RFC 9116 - security.txtVerifiedIETFrfc-editor.org
Inline markers like [1] jump to the matching reference above.