responsible disclosure

Following principled processes to attribute, mitigate, document, and communicate security, privacy, or safety incidents and vulnerabilities to relevant stakeholders in ways that limit harm and enable remediation.

responsibledisclosure

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Towards a Principled Framework for Disclosure Avoidance

Feb 10, 2025
MB
Michael B. Hawes
🏛️ U.S. Census Bureau | Iowa State University | University of Virginia

This paper addresses the core challenge faced by statistical agencies in selecting and designing disclosure avoidance systems (DAS): the difficulty of distinguishing between inherent system properties and implementation-specific choices. We propose the first principled evaluation framework that explicitly decouples “system essential attributes” from “implementation decisions.” Methodologically, the framework integrates risk assessment theory, statistical disclosure control (SDC) paradigm analysis, multi-dimensional constraint modeling, and iterative systems engineering—enabling dynamic trade-offs among privacy protection strength, data utility, and system adaptability under concurrent constraints of legal compliance, scientific validity, resource limitations, and stakeholder requirements. Our primary contribution is filling a critical gap in standardized DAS evaluation by delivering a practical, actionable framework. It supports evidence-based system selection and customized deployment, thereby enhancing the usability and operational agility of official statistics while ensuring regulatory compliance.

adapting to legal and scientific requirementsdistinguishing system features from implementationframework for disclosure avoidance

This study addresses two core challenges in large-scale security vulnerability notifications: fragmented multi-stakeholder coordination and persistent conflation between vulnerability disclosure and notification practices. Through cross-case qualitative meta-analysis, operational log reconstruction, and comparative analysis of policy evolution, we systematically distinguish—along objective, procedural, and ethical dimensions—the fundamental nature of vulnerability disclosure (repair-oriented, collaboration-centric) versus vulnerability notification (reach-oriented, scalability-focused). Building on this distinction, we propose the first “end-to-end notification operations framework” tailored for large-scale stakeholder outreach, encompassing message initiation, multi-channel adaptation, and response assessment, accompanied by a dedicated ethical guideline. The framework has been formally integrated into a draft revision of the industry-wide Vulnerability Notification Operations Standard.

Addressing challenges in notifying multiple stakeholders about vulnerabilitiesCompiling best practices for effective vulnerability communication strategiesDistinguishing between vulnerability disclosure and notification practices

This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.

critical infrastructurecyber safetycyber-physical systems

Privacy and Confidentiality Requirements Engineering for Process Data

May 16, 2025
FH
Fabian Haertel
🏛️ Technical University of Munich | Zumtobel Lighting GmbH

In process mining, real-world event logs are often inaccessible for sharing due to corporate privacy and confidentiality concerns—distinct from individual data privacy—posing a critical bottleneck for collaborative analysis. Method: This paper formally defines “confidentiality” for process data and introduces Privacy and Confidentiality Requirements Engineering (PCRE), a methodology integrating stakeholder co-modelling, structured expert interviews, and privacy-enhancing action design. PCRE systematically balances GDPR compliance, protection of business-sensitive information, and analytical utility. Contribution/Results: Empirical validation across two manufacturing enterprises demonstrates PCRE’s feasibility and reusability in high-sensitivity industrial settings. The framework delivers a practical, requirements-driven paradigm for conducting compliant and analytically viable process data analysis—bridging regulatory adherence with operational relevance in enterprise process intelligence.

Addressing confidentiality concerns in non-personal process dataBalancing trade-off between data utility and privacy in process miningDeveloping privacy-preserving techniques for event logs under GDPR

This study addresses the challenge of privacy communication in human–robot collaboration systems within Industry 5.0, where sensitive data monitoring raises significant privacy concerns that are often obscured by technical complexity, leading to mistrust and resistance among non-technical stakeholders. To bridge this gap, the authors propose a novel conceptual framework that integrates Privacy by Design principles with large language models (LLMs), leveraging LLMs for the first time in the requirements engineering process to automatically generate natural-language privacy reports tailored for non-technical audiences from representative human–robot monitoring scenarios. Evaluation across two industrial use cases demonstrates that the approach substantially enhances the comprehensibility of privacy information and supports informed decision-making, thereby addressing a critical accessibility gap in existing privacy communication mechanisms.

human-machine collaborationnon-technical stakeholdersprivacy communication

Latest Papers

What's happening recently
View more

Data Protection and Corporate Reputation Management in the Digital Era

Dec 16, 2025
GW
Gabriela Wojak
🏛️ I'M BRAND INSTITUTE Sp. z o.o. | Nowy Sącz School of Business - National Louis University | University College of Professional Education in Wroclaw | WSB Merito University in Toruń | Pomeranian Higher School in Starogard Gdanski | GLOBAL HYDROGEN spółka akcyjna | WSB Merito University in Gdańsk

This study uncovers an inherent tension among cybersecurity governance, data protection, and corporate reputation in digital transformation: despite high compliance readiness—75% of surveyed firms experienced at least one cyberattack within the past year—security incidents persist, with reputational damage and erosion of customer trust being the predominant consequences. Method: Drawing on an online diagnostic survey across multiple industries in Poland, the study applies the ISO/IEC 27001/27032 frameworks and a structured questionnaire, employing descriptive statistics and attributional analysis. Contribution/Results: It provides the first empirical identification of the “compliance–security paradox.” The study proposes a novel paradigm that integrates cybersecurity governance deeply into corporate communication and reputation management systems. It positions data protection as the cornerstone of digital trust and organizational resilience, reframing cybersecurity from a regulatory cost center to a strategic investment.

Analyzes cybersecurity governance integration with communication and reputation managementExamines cybersecurity's link to corporate reputation and data protectionInvestigates strategies for mitigating cyber risks and maintaining stakeholder trust

This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.

LLM-based securityrole-based agentic architecturesecure software engineering

This study addresses the pervasive delay in patching critical vulnerabilities (CVSS ≥ 9.0) following disclosure, which significantly exacerbates organizational cybersecurity risks. Analyzing 12.8% of critical vulnerabilities among 245,456 CVEs reported between 2009 and 2024, this work presents the first integrated approach combining large-scale quantitative analysis with in-depth case studies. It reveals that remediation lags are systematically constrained by organizational processes, resource endowments, and system complexity, with pronounced disparities across industry sectors. Beyond elucidating the systemic mechanisms underlying vulnerability management delays, the research offers actionable recommendations for optimizing incident response. These findings provide empirical grounding and practical guidance to enhance the effectiveness of critical vulnerability governance.

critical vulnerabilitiesCVSS scoredisclosure delay

This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.

Financial-Technology OrganisationInformation Security ManagementISMS Implementation

Traditional CVSS scores often fail to effectively prioritize vulnerability remediation in real-world attack scenarios. This work proposes a composite Key Risk Indicator (KRI) based on expected loss decomposition, which, for the first time, decouples threat, exposure, and business impact into distinct modeling components to enable risk-informed remediation decisions. The KRI model integrates the Known Exploited Vulnerabilities (KEV) catalog, over 280,000 CVE records, and metrics including EPSS, CVSS, and attack surface exposure. Empirical evaluation demonstrates that KRI achieves a ROC-AUC of 0.927 and an AUPRC of 0.223, significantly outperforming CVSS. Moreover, when prioritizing the top 500 vulnerabilities for remediation, KRI captures 92.3% of impact-weighted value and identifies 1.75 times more critically exploited vulnerabilities than EPSS.

CVSSKey Risk Indicatorsrisk reduction

Hot Scholars

DE

David Evans

University of Virginia, Computer Science
Adversarial Machine LearningPrivacy-Preserving Machine LearningComputer SecuritySecure Computation
NW

Ning Wang

School of Marine Engineering, Dalian Maritime University
Unmanned Marine VehiclesAutonomous SystemsGuidance and ControlIntelligent Nonlinear Modeling and Control
CL

Chen Liang

University of Connecticut
Future of WorkArtificial IntelligenceBias and DiscriminationPlatform Economy
IK

In Kyung Kim

Department of Economics, Sogang University
Industrial Organization
KI

Kyoo il Kim

Economics, Michigan State University
EconometricsIndustrial Organization