2015-06-22 10:57
in order to further manage information disclosure and the disposal of internet security vulnerability, network and information security committee of the internet society of china (isc) leads relevant organizations to draw up the self-discipline convention on disclosure and disposal of vulnerability information (called convention) under the guidance of ministry of industry and information technology (miit). on june 19, the signing ceremony was held and 32 companies committing to the pact.
with the rapid development and popularity of internet, more and more internet security incidents turn up. therefore, high risk vulnerabilities in information system become the main reason that cause internet security incident. according to cnvd, newly added general hardware and software vulnerabilities keep a rapid growth, about 20% annual year. the key infrastructure and important information system have vulnerabilities, which may cause huge potential safety hazard and utilized by hacker. it will not only threaten the safety of internet data and users’ personal information, but also the whole information system.
recently, the appearance and rapid development of domestic civil vulnerabilities platform have a positive effect on mobilizing the society, timely reminding and urging relevant affiliation to repair bugs and guard against risks, avoiding spreading. to give full play to these bugs, miit guide cncert to establish working relationships with civil vulnerabilities platform mainly deal with vulnerabilities in government sectors, major industries, and have received and managed more than 13,000 pieces of vulnerability information, which timely help to eliminate potential safety threats. however, there exist problems in discoursing vulnerabilities, which need to standardize. in addition, all parties need to work together to deal with vulnerabilities, and improve working efficiency, reduce threatens and economic losses.
signing convention is the first time to standardize reception, management and publish of vulnerability information by manner of self-discipline. the convention makes stipulations on duties and self-discipline clauses of vulnerabilities disclosure and management, with the principles of objective, timely, moderate. all parties should enhance cooperation, work actively to verify, evaluate, restore vulnerability information, and keep smooth interaction with users. the convention emphasizes that we should abide by the national policies and legislations, the regulations made by chinese government, better manage the vulnerabilities disclosure relating to government and important information system department. at the same time, users’ right to know the vulnerabilities and security interests should be guaranteed.
more than 40 departments, entities attend the signing ceremony.
with the rapid development and popularity of internet, more and more internet security incidents turn up. therefore, high risk vulnerabilities in information system become the main reason that cause internet security incident. according to cnvd, newly added general hardware and software vulnerabilities keep a rapid growth, about 20% annual year. the key infrastructure and important information system have vulnerabilities, which may cause huge potential safety hazard and utilized by hacker. it will not only threaten the safety of internet data and users’ personal information, but also the whole information system.
recently, the appearance and rapid development of domestic civil vulnerabilities platform have a positive effect on mobilizing the society, timely reminding and urging relevant affiliation to repair bugs and guard against risks, avoiding spreading. to give full play to these bugs, miit guide cncert to establish working relationships with civil vulnerabilities platform mainly deal with vulnerabilities in government sectors, major industries, and have received and managed more than 13,000 pieces of vulnerability information, which timely help to eliminate potential safety threats. however, there exist problems in discoursing vulnerabilities, which need to standardize. in addition, all parties need to work together to deal with vulnerabilities, and improve working efficiency, reduce threatens and economic losses.
signing convention is the first time to standardize reception, management and publish of vulnerability information by manner of self-discipline. the convention makes stipulations on duties and self-discipline clauses of vulnerabilities disclosure and management, with the principles of objective, timely, moderate. all parties should enhance cooperation, work actively to verify, evaluate, restore vulnerability information, and keep smooth interaction with users. the convention emphasizes that we should abide by the national policies and legislations, the regulations made by chinese government, better manage the vulnerabilities disclosure relating to government and important information system department. at the same time, users’ right to know the vulnerabilities and security interests should be guaranteed.
more than 40 departments, entities attend the signing ceremony.