As cyber threat activity groups and cybersecurity researchers focus more on enumerating and attacking industrial control systems, vendors have been challenged with how best to communicate vulnerabilities in their products to their customer base. Rockwell Automation has demonstrated its commitment to a transparent and supportive dialogue with the vulnerability research and disclosure community.
Rockwell Automation has formed a Product Security Incident Response Team (RA PSIRT) that initiates its vulnerability management process. Rockwell is one of the first Industrial Control System (ICS) vendors to align their Vulnerability Handling and Disclosure processes with IEC standards (IEC 29147 and 30111).
Rockwell also works closely with national response organizations, such as the American Industrial Control System Computer Emergency Response Team (ICS-CERT), to broadcast vulnerabilities to a larger audience.
...