Disclosure Policy

Noun · Security & Infosec

Definitions

  1. A published policy explaining how security researchers or outsiders should report vulnerabilities, what behavior is allowed, and how the organization will respond. A good disclosure policy reduces confusion and makes coordinated vulnerability handling more predictable.

    In plain English: A public set of rules for reporting security vulnerabilities to an organization.

    Example: "The new disclosure policy gave researchers a clear email path and promised not to threaten good-faith reporting."

Related Terms