Coordinated Vulnerability Disclosure Policies in the EU

Jurisdiction
European Union
Region
Europe
Requirement
Recommended
Organization
European Union Agency for Cybersecurity (ENISA)
Provision
Section 4
Applies to
EU Member States
Date
April 2022
Description

Encourages EU member states to implement CVD policies by providing recommendations for how to overcome the associated legal, economic, political, operational, and crisis management challenges. In the document, ENISA also hinted that, in the future, it might provide clear guidance to countries about how to establish a CVD policy, publish countries’ best practices and challenges, and publishing templates upon which countries can draft their policies. Since April 2022, ENISA has published updated guidance and practical templates to assist member states in establishing effective CVD policies.