Vulnerability Disclosure
502 CVE Program partners with structured CNA data
secid:disclosure/cloudsecurityalliance.org/responsible-disclosure
→ channels: GitHub PVR (preferred), security@cloudsecurityalliance.org
→ scope: websites, services, GitHub repos, AI prompts
→ policy: coordinated disclosure, 90-day timeline, safe harbor
Every CNA now has structured fields: formal CNA ID (CNA-2005-0006), CVE Program UUID, last assigned CVE (staleness indicator), disclosure policy URL, and security.txt status.
For members: "Who handles CVEs for this vendor?" → one query → CNA role, scope, contacts, policy.
For CSA security team: the authoritative reference for CSA's own disclosure process.