Jurisdiction
Region
Requirement
Policy
Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), made under the Cyber Security Act 2024
Applies to
Manufacturers of relevant connectable products (consumer IoT/smart devices) acquired by consumers in Australia
Provision
Schedule 1, Part 1, clause 3 — Requirements relating to reports of security issues
Description

"(1) The manufacturer of a relevant connectable product must publish the information in subclause (2) on how a person is to report security issues in relation to the product... (2) The information that must be published is: (a) at least one point of contact to allow a person to report security issues to the manufacturer; and (b) when a person who makes such a report will receive: (i) an acknowledgement of the receipt of the report; and (ii) status updates until the resolution of the reported security issues. (3) The information published must be accessible, clear and transparent, and must be made available to a person: (a) without prior request... (b) in English; and (c) free of charge; and (d) without requesting the provision of personal information about the person."

Date
March 4, 2026
Organization
Department of Home Affairs
Jurisdiction
Region
Requirement
Policy
Protective Security Policy Framework - Policy 11 - Robust ICT Systems
Applies to
Australian Government entities
Provision
C.6
Description

C.6 Vulnerability Disclosure Program 

60. Requirement 4 mandates that all entities must have in place a vulnerability disclosure program. This includes having a publicly available vulnerability disclosure policy supported by processes and procedures for receiving, verifying, resolving and reporting on security vulnerabilities disclosed by both internal and external sources. 

61. Implementing a vulnerability disclosure program, based on responsible disclosure, can assist entities, vendors and service providers to improve the security of their products and services as it provides a way for security researchers, customers and members of the public to responsibly notify them of potential security vulnerabilities in a coordinated manner. Furthermore, following the verification and resolution of a reported security vulnerability, it can assist entities, vendors and service providers in notifying their customers of any security vulnerabilities that have been discovered in their products and services and any recommended security patches, updates or mitigations. 

62. For guidance on the creation and maintenance of vulnerability disclosure programs, see the Information Security Manual and Guidelines for Software Development.

A new iteration of the Guidelines for Software Development, including updated guidance on vulnerability disclosure programs, was published in March 2025.

Date
July 29, 2022
Organization
Australian Department of Home Affairs
Jurisdiction
Region
Requirement
Policy
Code of Practice: Securing the Internet of Things for Consumers
Applies to
Device Manufacturers, IoT Service Providers and Mobile Application Developers
Provision
Principle 2
Description

Principle 2: Implement a vulnerability disclosure policy 

IoT device manufacturers, IoT service providers and mobile application developers should provide a public point of contact as part of a vulnerability disclosure policy in order for security researchers and others to report issues. Disclosed vulnerabilities should be acted on in a timely manner. Implementing a bug bounty program encourages and rewards the cyber security community for identifying and reporting vulnerabilities, thereby facilitating the responsible and coordinated disclosure and remediation of vulnerabilities. 

Primarily applies to Device Manufacturers, IoT Service Providers and Mobile Application Developers.

Date
2020
Organization
Australian Government
Jurisdiction
Region
Requirement
Policy
Information Security Manual (ISM)
Applies to
Large companies, Government agencies
Provision
Pg. 106 (Controls ISM-1616, ISM-1755, ISM-1756, ISM-1717)
Description
Control: ISM-1616; Revision: 0; Updated: Aug-20; Applicability: All; Essential Eight: N/A A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.  Control: ISM-1755; Revision: 1; Updated: Dec-22; Applicability: All; Essential Eight: N/A A vulnerability disclosure policy is developed, implemented and maintained.  Control: ISM-1756; Revision: 1; Updated: Dec-22; Applicability: All; Essential Eight: N/A Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained. Control: ISM-1717; Revision: 2; Updated: Sep-23; Applicability: All; Essential Eight: N/A A ‘security.txt’ file is hosted for all internet-facing organisational domains to assist in the responsible disclosure of vulnerabilities in an organisation’s products and services. 
Date
September 2023
Organization
Australian Signals Directorate (ASD)