Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)

Tommo (Global CVD Project Lead · JP Coordination Center), Justin Murphy (Vulnerability Analyst · CISA)

CVE/FIRST VulnCon 2025 · Main Stage

Overview

In an increasingly interconnected digital landscape, the effective management and disclosure of cybersecurity vulnerabilities are paramount. This talk, delivered by Tommoito of JPCERT/CC and Justin Murphy of CISA, introduces a significant new initiative: the establishment of a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD COP). The presentation delves into the critical need for enhanced international cooperation in CVD, highlighting the complexities introduced by global supply chains, diverse cultural contexts, and evolving regulatory frameworks such as the EU Cyber Resilience Act (CRA).

Watch on YouTube

Visual summary for Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD) by Tommo, Justin Murphy
Visual summary for Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD) by Tommo, Justin Murphy

Key moments

  1. 0:00 Introduction to Global CVD Community of Practice
  2. 1:50 Defining Coordinated Vulnerability Disclosure (CVD)
  3. 2:40 CVD basic stakeholders and information flow
  4. 3:40 The unique facilitator role of CVD coordinators
  5. 4:10 Emphasizing CVD as a truly global process
  6. 6:00 CISA's mission and focus in CVD
  7. 7:20 JPCERT/CC's role and motivation as a CVD coordinator

Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)

Speakers: Tommoito, Global CVD Project Lead, JPCERT/CC; Justin Murphy, Vulnerability Analyst, CISA

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=udBqjmuVRGg

Overview

In an increasingly interconnected digital landscape, the effective management and disclosure of cybersecurity vulnerabilities are paramount. This talk, delivered by Tommoito of JPCERT/CC and Justin Murphy of CISA, introduces a significant new initiative: the establishment of a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD COP). The presentation delves into the critical need for enhanced international cooperation in CVD, highlighting the complexities introduced by global supply chains, diverse cultural contexts, and evolving regulatory frameworks such as the EU Cyber Resilience Act (CRA).

The speakers, both representing national vulnerability coordination centers and serving as root CVE Numbering Authorities (CNAs), underscore the unique position of third-party coordinators in facilitating vulnerability remediation. The CVD COP aims to unite these specialized entities from around the world to share knowledge, harmonize practices, and collectively improve the global effectiveness of vulnerability coordination. This effort is particularly timely as the importance of robust CVD processes continues to grow in mitigating widespread cyber risks.

The initiative represents a proactive step towards overcoming long-standing challenges in global CVD, including communication gaps, differing operational understandings, and the necessity to balance diverse stakeholder interests. By fostering a dedicated community for government-affiliated coordinators, the CVD COP seeks to build capacity, streamline information flow, and ultimately reduce risks to users and society by ensuring vulnerabilities are addressed swiftly and effectively across international borders.

Background

▶ Watch: Introduction to Global CVD Community of Practice (0:00)

Coordinated Vulnerability Disclosure (CVD) is defined as the systematic process of gathering, coordinating, and disclosing vulnerability information. It is recognized as a global good practice, often involving numerous stakeholders across intricate global product supply chains. The speakers emphasized that vulnerability information inherently flows through these complex chains, making CVD a truly global endeavor. A particularly challenging aspect is Multi-Party CVD (MPCVD), where multiple vendors and suppliers participate. The complexity of MPCVD cases directly correlates with the complexity of the underlying supply chains, presenting significant coordination hurdles. The growing importance of CVD is further underscored by its integration into various international regulations and laws, such as the EU Cyber Resilience Act (CRA).

The basic information flow in CVD involves reporters or finders who discover vulnerabilities and report them, typically to a vendor. The vendor then confirms the vulnerability, develops patches or updates, and eventually, the information is publicly disclosed, often through a vulnerability advisory, allowing users to take necessary actions. Crucially, a distinct role exists for coordinators, such as JPCERT/CC and CISA. These entities do not find vulnerabilities or own products but act as neutral third parties, facilitating communication, supporting the process, and ensuring smooth remediation. They serve as "bridge builders" and, when necessary, "de-escalators" in potentially contentious situations.

Both CISA and JPCERT/CC operate as national coordinators and root CNAs, responsible for assigning Common Vulnerabilities and Exposures (CVEs). CISA focuses on coordinating remediation and disclosure for newly identified cyber vulnerabilities in products and services, with a strong emphasis on the nation’s critical infrastructure, federal executive branches, and a broad scope covering IT, OT, ICS, IoT, and AI. JPCERT/CC, similarly, coordinates both domestic and overseas issues within Japan's vulnerability handling framework, aiming to reduce risks to users and society.

The concept of a dedicated working group for vulnerability coordination is not new. Previous efforts include a 2004 document by the National Infrastructure Advisory Council (NIAC), a 2015 document by ANA (Automotive Information Sharing and Analysis Center) on vulnerability disclosure, the CERT Guide from 2017 (updated in 2019), and a 2020 document on MPCVD by the FIRST Vulnerability Coordination SIG. An ISO standard (ISO/IEC 29147:2020) for vulnerability disclosure and ISO/IEC 30111:2019 for vulnerability handling processes also exist. While the FIRST SIG is still technically active, the speakers noted that it lacks active meetings and development work, prompting the decision to establish a new, dedicated group.

The motivation for creating the CVD COP stemmed from several key observations:

  • CVD is a global good practice: requiring enhanced global information cooperation.
  • Capacity development: Jointly developing capabilities is essential.
  • Overcoming barriers: CVD cases often fail due to cultural or language gaps between stakeholders.
  • Knowledge and experience sharing: Facilitating this is crucial to finding solutions for common challenges.
  • Harmonization: The industry has long expressed a need for government and international organizations to come together to harmonize common guidance and best practices around CVD.

This new community specifically targets government entities or organizations working in an official government capacity to conduct CVD, recognizing their unique role and need for a specialized forum to improve collective practice.

Key Findings

▶ Watch: CVD basic stakeholders and information flow (2:40)

The central finding and contribution of this talk is the successful establishment of the Global Community of Practice on Coordinated Vulnerability Disclosure (CVD COP). This initiative was formally launched in December of last year, holding its first official meeting on December 5th. Since then, the community has been meeting monthly, demonstrating its commitment to ongoing collaboration.

The CVD COP is structured as a standard working group, currently led by three co-chairs: Tommoito (JPCERT/CC), Justin Murphy (CISA), and Ali from the UK. As of the presentation, the community boasts 17 different participants representing 14 different countries (or 15 different regions, including entities like ENISA). This diverse membership spans various global locales, cultures, and even different stages of their respective CVD journeys, from nascent programs to well-established ones. This diversity is seen as a significant strength, offering opportunities for mutual learning and mentorship.

A foundational achievement of the group is the finalization of its community charter, which articulates its ultimate goals and objectives. The core purpose of the CVD COP is to bring together CVD subject matter experts who operate in the role of third-party coordinators, particularly those from government entities or organizations working in an official capacity with governments to conduct CVD. The overarching goal is straightforward: to "get better at CVD" collectively.

Crucially, the speakers emphasized what the CVD COP is not: it is not a body for forming official policy, not a regulating body, and not a standards group. Instead, its mission is to bring together like-minded individuals and organizations to harmonize and develop common guidance around CVD. This focus on practical improvement and shared understanding, rather than prescriptive rules, positions the COP as a facilitator for broader community benefit. The group aims to leverage the unique position of third-party coordinators to enhance the overall CVD ecosystem.

Technical Deep Dive

▶ Watch: The unique facilitator role of CVD coordinators (3:40)

While the talk focuses on community building and process, several technical and organizational aspects underpin the CVD COP's mission. At its core, Coordinated Vulnerability Disclosure (CVD) is a structured process designed to manage the lifecycle of vulnerabilities. This process involves precise information flows and clearly defined roles: from the initial discovery and reporting by finders or reporters, through vendor analysis, patching, and updates, to the eventual public disclosure via advisories, and finally, user action. The critical role of coordinators like JPCERT/CC and CISA is to act as neutral third parties, facilitating communication and ensuring the smooth progression of this process, particularly in complex Multi-Party CVD (MPCVD) scenarios involving numerous vendors across global supply chains.

A key technical infrastructure supporting global vulnerability management is the CVE Program, which assigns unique identifiers (CVE IDs) to publicly known cybersecurity vulnerabilities. Both Tommoito and Justin Murphy highlighted their organizations' roles as root CVE Numbering Authorities (CNAs). Root CNAs oversee other CNAs, ensuring consistent identification and categorization of vulnerabilities. This technical standardization is fundamental to enabling effective coordination, allowing stakeholders worldwide to refer to the same vulnerability with a common identifier, regardless of language or regional differences. CISA, for instance, is a top-level root CNA for ICS and medical device vendors, illustrating the specialized nature of their coordination efforts.

The CVD COP itself is an organizational architecture designed to foster collaboration. Its community charter serves as a foundational document, outlining the group's scope, objectives, and operational principles. While the detailed contents of the charter were not fully disclosed, its existence signifies a formal commitment to a shared vision. The group operates through monthly meetings and plans to utilize GitHub as a private repository for asynchronous communication and work. This choice of a version-controlled platform suggests an intention to manage shared documents, best practices, and potentially even draft guidance in a collaborative and trackable manner, moving beyond mere synchronous discussions.

The speakers also articulated specific challenges inherent in establishing such a global community, which can be seen as "technical" in the sense of overcoming systemic hurdles in complex socio-technical systems:

  • Differing "CVD images": Members often hold varied mental models of CVD, with some focusing on the initial coordination phase and others on post-disclosure information distribution. This necessitates careful alignment of terminology and scope.
  • Different levels of understanding: While acknowledged as a "beautiful" diversity, varying levels of experience and understanding require strategies for knowledge transfer and capacity building within the group.
  • Participation dynamics: The existence of "more vocal" and "less vocal" organizations points to the need for facilitation techniques that ensure all voices are heard and contributions are balanced.
  • Membership balance: The current predominance of government-related organizations highlights a structural challenge. For the COP's guidance to be truly impactful and holistic, it needs to balance its perspectives with input from other critical stakeholders in the broader ecosystem, such as private sector vendors, researchers, and end-users.

These challenges, while not involving lines of code, represent significant technical obstacles in building a robust, effective, and globally impactful community of practice that can genuinely harmonize complex, multi-stakeholder processes like CVD. The COP's ability to address these internal dynamics will dictate its success in developing widely applicable and accepted guidance.

Demo / Proof of Concept

▶ Watch: CISA's mission and focus in CVD (6:00)

This presentation did not feature a traditional technical demonstration or a live proof of concept in the sense of showing code or exploiting a vulnerability. Instead, the "proof of concept" lies in the successful establishment and ongoing operation of the Global Community of Practice on Coordinated Vulnerability Disclosure (CVD COP) itself.

The speakers effectively demonstrated the viability and necessity of this initiative by detailing its formation, structure, and early achievements. The fact that the group was established in December of the previous year, held its first official meeting on December 5th, has been meeting monthly ever since, and has already finalized a community charter with 17 participants from 14 countries/15 regions serves as compelling evidence of its active status and potential impact. The passionate commitment of the co-chairs, Tommoito and Justin Murphy, and the diverse engagement from various national coordinators underscore the practical demand for such a collaborative forum. While no software or system was showcased, the very existence and current state of the CVD COP stand as a testament to the community's ability to coalesce around a shared objective of improving global vulnerability coordination.

Defensive Implications

▶ Watch: JPCERT/CC's role and motivation as a CVD coordinator (7:20)

The establishment of the CVD COP carries significant defensive implications for organizations, security professionals, and end-users worldwide. At its core, the initiative aims to enhance the effectiveness of vulnerability coordination globally, which directly translates to a stronger defensive posture against cyber threats.

Firstly, harmonized guidance and best practices for CVD, developed by a consortium of experienced national coordinators, will provide clearer expectations for all stakeholders. This means that vulnerability reporters, vendors, and other parties will have a more consistent framework for engaging in disclosure processes. For defenders, this consistency can lead to faster and more predictable vulnerability remediation cycles, reducing the window of opportunity for attackers to exploit known weaknesses. When vendors and product owners follow clearer, globally recognized CVD practices, the deployment of patches and updates becomes more efficient, directly benefiting the security of deployed systems and services.

Secondly, the focus on overcoming cultural and language gaps in CVD is crucial for global defense. In today's interconnected supply chains, a vulnerability in one component can affect products globally. Miscommunications or delays due to cultural differences can impede the rapid resolution of critical vulnerabilities. By fostering a community that addresses these nuances, the CVD COP helps ensure that vulnerability information flows smoothly across borders, enabling timely defensive actions by affected organizations and users, regardless of their geographic location.

Thirdly, the knowledge and experience sharing among national coordinators will lead to improved handling of complex Multi-Party CVD (MPCVD) cases. These scenarios, which often involve numerous vendors and intricate supply chains, are notoriously difficult to coordinate. A community of practice allows coordinators to pool their expertise, share lessons learned from challenging cases, and collectively devise more effective strategies. For defenders, this means that even the most complex vulnerabilities affecting multiple products or services are more likely to be coordinated efficiently, leading to comprehensive and widespread remediation. This ultimately reduces systemic risk across various sectors, including critical infrastructure.

Finally, the CVD COP's emphasis on capacity building and its invitation for broader community feedback (including from vendors and the private sector) indicates a commitment to a holistic improvement of the CVD ecosystem. As more organizations adopt robust CVD practices, the overall security hygiene improves. Defenders should view this initiative as a foundational effort that will yield long-term benefits in terms of improved vulnerability intelligence, more reliable patch management, and a more resilient global digital infrastructure. Engaging with such initiatives, even indirectly, by providing feedback or adopting their eventual guidance, allows defenders to contribute to and benefit from a stronger collective defense.

Key Takeaways

  • CVD is a Global Imperative: Coordinated Vulnerability Disclosure (CVD) is a critical global practice, essential for reducing risks to users and society, especially given the complexity of global supply chains and the increasing integration of CVD into regulations like the EU CRA.
  • The CVD COP Fills a Critical Gap: The newly established Global Community of Practice on Coordinated Vulnerability Disclosure (CVD COP) provides a dedicated forum for government-affiliated third-party coordinators to collaborate, a role previously underserved despite existing efforts.
  • Focus on Harmonization and Capacity Building: The CVD COP is not a regulatory or standards body but aims to harmonize practices, share knowledge, and build capacity among its members to enhance the global effectiveness of vulnerability coordination.
  • Addressing Challenges in Global Coordination: The community actively recognizes and is working to overcome significant hurdles, including diverse understandings of CVD, cultural/language barriers, and the need to balance perspectives across various stakeholders.
  • Coordinators as Bridge-Builders: Organizations like JPCERT/CC and CISA play a unique and vital role as neutral third-party coordinators, acting as facilitators and "bridge-builders" in the complex, multi-stakeholder CVD process.
  • Community Input is Valued: The CVD COP is actively seeking feedback from the broader cybersecurity community, including vendors and private sector entities, to define its future deliverables and ensure its work addresses the most pressing needs in global CVD.

About the Speaker(s)

Tommoito is the Global CVD Project Lead at JPCERT/CC, the Japan Computer Emergency Response Team Coordination Center. His professional passion lies in Coordinated Vulnerability Disclosure (CVD), Software Bill of Materials (SBOM), Vulnerability Exploitability eXchange (VEX), and international cooperation in cybersecurity. JPCERT/CC operates as a national CVD coordinator within Japan's framework and also serves as a root CVE Numbering Authority (CNA).

Justin Murphy is a Vulnerability Analyst at CISA, the Cybersecurity and Infrastructure Security Agency. He is deeply passionate about Coordinated Vulnerability Disclosure (CVD) and has been actively involved with the SBOM/VEX community and various standards communities for several years. CISA is a prominent national CVD coordinator in the United States, focusing on critical infrastructure and federal agencies, and also functions as a top-level root CVE Numbering Authority (CNA).

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-intentioned policy/community talk from two credible speakers who actually hold the seats they're describing. JPCERT/CC and CISA standing up a formal global CVD community of practice is a real thing that matters to practitioners in this space, and the speakers are close enough to the work to speak with authority. But the talk itself delivers less signal than the initiative deserves — it's heavy on framing, light on specifics, and the 'proof of concept' is just the fact that the group exists and has met monthly. For a VulnCon audience that already understands CVD mechanics, there's not much here to act on yet.

Heather Calloway (CISO) — SOLID

A competent and timely announcement talk from credible practitioners at JPCERT/CC and CISA. The CVD COP addresses a real coordination gap in global vulnerability management — the absence of an active, government-affiliated working group for third-party coordinators — and its early traction (17 participants, 14 countries, finalized charter) is genuinely encouraging. But this is an initiative launch, not a findings presentation. It tells the audience that a community now exists and that it intends to improve CVD globally. It does not yet tell security leaders, vendors, or policy officials what that community will actually produce, how its outputs will differ from prior guidance, or what…

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025