The NSA, CISA, Japan's JPCERT/CC, and the Netherlands' NCSC-NL jointly published a Cybersecurity Information Sheet titled "Establishing a Coordinated Vulnerability Disclosure Program to Work with Security Researchers." The document is aimed at helping organizations build formal processes for receiving, evaluating, and acting on vulnerability reports submitted by external researchers.
Coordinated vulnerability disclosure (CVD) programs have become a recognized best practice in medical device cybersecurity — the FDA now expects device manufacturers to maintain them as part of postmarket security management. For HDOs, having a parallel internal process matters too: when a researcher or vendor notifies your organization of a flaw in connected equipment, a defined intake and response workflow determines how fast a risk gets contained.
Source: TechNation