A Research Report from the NTIA Awareness and Adoption Group Contents Executive Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3Response and Demographics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4Key Findings and Analyses – Researcher Survey . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Key Findings and Analyses – Technology Provider and Operator Survey . . . . . . . . . . . . . . . . 7Coordinating Disclosure for Improved Outcomes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11Appendix A – Challenges of Methodology. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12Appendix B – Researcher Survey . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12Appendix C – Technology Provider and Operator Survey . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 Executive Summary In September 2015, the National Telecommunications and Information Administration (NTIA) convened a multi-stakeholderprocess to investigate software vulnerability disclosure and handling practices. The process was open to any interestedparticipant and included members from business, government, and civil society. Members organized into three working groupsto study different aspects of vulnerability disclosure and handling. This report is a product of the “Awareness and AdoptionWorking Group,” which focused on increasing understanding and use of best practices. To assess the state of the field, the working group surveyed populations of software vendors and security researchers.Questions focused on past or current behavior for reporting or responding to vulnerabilities, as well as processes that worked orcould be improved. There were 414 responses to the researcher survey and 285 to the vendor survey. Key findings from each aresummarized below. Researcher survey •The vast majority of researchers (92%) generally engage in some form of coordinated vulnerability disclosure.•When they have gone a different route (e.g., public disclosure) it has generally been because of frustrated expectations,mostly around communication.•The threat of legal action was cited by 60% of researchers as a reason they might not work with a vendor to disclose.•Only 15% of researchers expected a bounty in return for disclosure, but 70% expected regular communication about thebug. Vendor survey •Vendor responses were generally separable into “more mature” and “less mature” categories. Most of the more maturevendors (between 60% and 80%) used all the processes described in the survey.•Most mature technology providers and operators (76%) look internally to develop vulnerability handling procedures, withsmaller proportions looking at their peers or at international standards for guidance.•Mature vendors reported that a sense of corporate responsibility or the desires of their customers were the reasons theyhad a disclosure policy.•Only one in three surveyed companies considered and/or required suppliers to have their own vulnerability handlingprocedures. This data can help guide future efforts to increase awareness and adoption. In particular, efforts to improve communicationbetween researchers and vendors should encourage more coordinated, rather than straight-to-public, disclosure. Removinglegal barriers, whether through changes in law or clear vulnerability handling policies that indemnify researchers, can also help.Both mature and less mature companies should be urged to look at external standards, such as ISOs, to better understandcost-savings across the software development lifecycle from the implementation of vulnerability handling processes. Introduction As software and technology systems become increasinglyinterconnected and complex, the likelihood they will containvulnerabilities increases. As these systems become integratedinto a vast array of products and services, the potential forthose vulnerabilities to negatively impact users in profoundways is becoming more significant. Vulnerabilities createopportunities for malicious attackers to commit cybercrimeor disrupt user activity. Although vendors seek to identify andremediate vulnerabilities before their products and services are brought to market, testing for everything is impossible. As a result, What is a vulnerability? Vulnerabilities are weaknesses of software, hardware, or online servicesthat can be used to damage the confidentiality, integrity, or availability ofthose systems or the data they store. Finding these vulnerabilities and in-forming a