Skip to main content
Image coming soon

ISO/IEC 29147:2018 Vulnerability Disclosure Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
ISO/IEC 29147:2018 · Vulnerability Disclosure · Evidence & Implementation Kit
Give researchers a way to report, and users a way to protect themselves, with a vulnerability disclosure process built to ISO 29147.
Every element of vulnerability disclosure handed to you as an adopt-ready control, with the coordination nuance, the exact evidence an assessor examines, and the finding they most often raise.
Disclosure-ready in a weekend, not a quarter.

Here is the honest situation. Customers, security researchers and a growing list of regulations now expect a vendor to have a vulnerability disclosure process: an advertised way to report, timely acknowledgement, and clear advisories. ISO 29147 is the reference for doing it. The hard part is standing up the policy, the reporting channel, the communication and the advisory process, and evidencing them, before a researcher tests you in public. Building that from a guidance document is weeks of work.

This Kit removes the build. It is the ISO 29147 disclosure policy, reporting, advisory and coordination process as adopt-ready controls you personalize in a weekend.

What you get, the moment you buy

31
Controls across the disclosure process. Every element from the policy and reporting channel through advisories, coordination and supporting the process. Personalize and you are done.
31
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus the finding they most often raise, and the disclosure nuance that catches vendors out.
1
29147 Control Matrix, pre-built. Every control in a working spreadsheet, ready to record your implementation, status and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook tells you your readiness as a single percentage, and exactly what to fix next.

Grounded in ISO/IEC 29147:2018, the disclosure companion to ISO/IEC 30111 handling, with the advertised reporting channel, advisory elements and coordinated disclosure called out. Editable Word and Excel files.

Coordination, not surprise
If a researcher cannot report to you, they may go public. ISO 29147 builds the advertised channel, the acknowledgement, and the coordinated advisory so the fix is ready when the vulnerability is known. This Kit makes that process concrete and evidenced.

What one control looks like

This is the foundational control, establishing and publishing a vulnerability disclosure policy. All 31 are built to this depth.

VD-1 Establish and publish a vulnerability disclosure policy DISCLOSURE POLICY
Adopt this control

[Vendor] shall define, document, and publish a vulnerability disclosure policy that describes how anyone may report a suspected vulnerability in [Vendor] products or services. The policy is owned by a named function, approved by management, kept current, and reachable from a stable, well known location so reporters can find it without prior contact.

Evidence an assessor examines
  • The published vulnerability disclosure policy and its public URL
  • Approval record showing management sign off and the accountable owner
  • Version history or review dates confirming the policy is maintained
  • Web analytics or link map showing the policy is reachable from the main site
Common finding they raise: A policy exists internally but is not published where an outside reporter can find it, so reports arrive through unmonitored channels or not at all.

Why this is not another template pack

  • The evidence is the point. A promise to accept reports is not a process. This tells you exactly what an assessor examines and the finding they raise, for every element, including the advisory content.
  • Coordination built in. The advertised channel, acknowledgement, communication and coordinated advisory timing are built in, so the fix is ready when the vulnerability is public.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. 29147 pairs with ISO 30111 handling and your secure development lifecycle, so your product security work is one program.

Who buys this

Product and platform vendors that need a credible disclosure process, security and PSIRT leads who own it, and consultants standing one up. Whether it is your first disclosure policy or a maturity uplift, you save weeks and walk in with the policy, channel and advisories ready.

By the end of the weekend you will have
✓  A control for every element of ISO 29147
✓  A completed 29147 control matrix
✓  The evidence an assessor examines
✓  Your reporting channel and advisory process anchored
✓  A readiness percentage and a fix list
✓  The common findings closed before a review

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

How does it relate to ISO 30111? 29147 covers disclosure (receiving and publishing); ISO 30111 covers the internal handling process. This Kit is the disclosure side, and points to the handling link.

Does it cover advisories? Yes. The content and elements of a security advisory, and the timing, are covered as their own controls.

Do I need a bug bounty? No. 29147 is about a disclosure process, not a paid program. The Kit builds the process; a bounty is optional on top.

What if it is not for me? A 30-day money-back guarantee.

Do not let a researcher find no way to report.
Standing up a disclosure process is fast with the Kit. It is instant, and it is guaranteed.
Add it to your cart and open your disclosure channel this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com