Here is the honest situation. Customers, security researchers and a growing list of regulations now expect a vendor to have a vulnerability disclosure process: an advertised way to report, timely acknowledgement, and clear advisories. ISO 29147 is the reference for doing it. The hard part is standing up the policy, the reporting channel, the communication and the advisory process, and evidencing them, before a researcher tests you in public. Building that from a guidance document is weeks of work.
This Kit removes the build. It is the ISO 29147 disclosure policy, reporting, advisory and coordination process as adopt-ready controls you personalize in a weekend.
What you get, the moment you buy
Grounded in ISO/IEC 29147:2018, the disclosure companion to ISO/IEC 30111 handling, with the advertised reporting channel, advisory elements and coordinated disclosure called out. Editable Word and Excel files.
What one control looks like
This is the foundational control, establishing and publishing a vulnerability disclosure policy. All 31 are built to this depth.
Why this is not another template pack
- The evidence is the point. A promise to accept reports is not a process. This tells you exactly what an assessor examines and the finding they raise, for every element, including the advisory content.
- Coordination built in. The advertised channel, acknowledgement, communication and coordinated advisory timing are built in, so the fix is ready when the vulnerability is public.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. 29147 pairs with ISO 30111 handling and your secure development lifecycle, so your product security work is one program.
Who buys this
Product and platform vendors that need a credible disclosure process, security and PSIRT leads who own it, and consultants standing one up. Whether it is your first disclosure policy or a maturity uplift, you save weeks and walk in with the policy, channel and advisories ready.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
How does it relate to ISO 30111? 29147 covers disclosure (receiving and publishing); ISO 30111 covers the internal handling process. This Kit is the disclosure side, and points to the handling link.
Does it cover advisories? Yes. The content and elements of a security advisory, and the timing, are covered as their own controls.
Do I need a bug bounty? No. 29147 is about a disclosure process, not a paid program. The Kit builds the process; a bounty is optional on top.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com