<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.christey-wysopal-vuln-disclosure" target="https://datatracker.ietf.org/doc/html/draft-christey-wysopal-vuln-disclosure-00">
   <front>
      <title>Responsible Vulnerability Disclosure Process
</title>
      <author initials="S." surname="Christey" fullname="SteQven Christey">
         </author>
      <author initials="C." surname="Wysopal" fullname="Chris Wysopal">
         </author>
      <date month="February" day="15" year="2002" />
      <abstract>
	 <t>New vulnerabilities in software and hardware products are discovered
and publicized on a daily basis.  The disclosure of vulnerability
information has been a divisive topic for years.  During the process
of disclosure, many vendors, security researchers, and other parties
follow a variety of unwritten or informal guidelines for how they
interact and share information.  Some parties may be unaware of these
guidelines, or they may intentionally ignore them.  This state of
affairs can make it difficult to achieve a satisfactory outcome for
everyone who uses or is affected by vulnerability information. 

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-christey-wysopal-vuln-disclosure-00" />
   
</reference>
