课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Ethical disclosure

Ethical disclosure

- [Narrator] Vulnerability researchers and other cybersecurity professionals sometimes discover previously unknown vulnerabilities. These vulnerabilities might be flaws in a software application, operating system, hardware device, virtual appliance, or any other element of the technology infrastructure. This knowledge can be both powerful and dangerous, and it's incumbent upon security professionals to handle this information responsibly and ethically. When a researcher discovers a vulnerability that nobody else has yet discovered, they have a zero day vulnerability on their hands. This simply means that a vulnerability exists for which there is no known fix, and in fact, most or all of the cybersecurity community is unaware of the vulnerability. This initial discovery marks the beginning of a period known as the window of vulnerability. During the window of vulnerability, the zero day vulnerability is extremely effective because not only is there no patch available to correct it, but…

内容