COORDINATED VULNERABILITY DISCLOSURE PROCESS KEY DIMENSIONS SET
DOI:
https://doi.org/10.35363/ViA.sts.2025.143Keywords:
CVD, vulnerability reporting, cybersecurity, CVD process key dimensionsAbstract
Since the enforcement of Directive (EU) 2022/2555 mandating the implementation of Coordinated Vulnerability Disclosure (CVD) processes, each EU Member State has adopted its own national approach. While some countries still rely on email-based systems to receive and process CVD reports, Latvia has taken a significant step forward by developing a dedicated digital platform for CVD management. However, a common issue across all implementations is the lack of a structured approach to the development of CVD programs when viewed through multiple dimensions. As a result, the failure to examine and address various dimensions, such as legal, technical, organizational, societal aspects and others limit the overall effectiveness and maturity of the CVD process.

