Blueprint: Coordinated Vulnerability Disclosure (CVD) Adaption and Adoption Guide for Industry To Create Their Own CVD Program
This guide provides a series of steps and guidance for electric vehicle supply equipment (EVSE) industry members to set up their own coordinated vulnerability disclosure (CVD) program by utilizing the Software Engineering Institute/Computer Emergency Response Team (SEI/CERT)’s CVD how-to guide. Due to the complexity of CVD, and with the existing resources out there, this guide is intended that this portion of the blueprint is an extension of the CVD how-to guide, not meant as a replacement. This guide is meant to outline a process for what to do when you discover a vulnerability on EVSE equipment. It is written for developers, vendors and security researchers as well as management. This is not a technical document. It is meant to be accessible for both technical and non-technical roles.