Cyber Confidence-Building Measures

CBM 16: Sharing vulnerability information

Organization for Security and Co-operation in Europe

OSCEPartially implemented2016

Measure

CBM 16 (2016): Participating States will, on a voluntary basis, encourage responsible reporting of vulnerabilities affecting the security of and in the use of ICTs and share associated information on available remedies to such vulnerabilities, including with relevant segments of the ICT business and industry, with the goal of increasing co-operation and transparency within the OSCE region. OSCE participating States agree that such information exchange, when occurring between States, should use appropriately authorized and protected communication channels, including the contact points designated in line with CBM 8 of Permanent Council Decision No. 1106, with a view to avoiding duplication.

Background: This CBM encourages participating states to promote responsible vulnerability disclosure and to share information on remedies, particularly with private actors. This includes fostering CVD policies and establishing national processes. It emphasizes the need for a multistakeholder approach, thereby linking it closely to CBM 14 on PPPs. To safeguard sensitive information exchanges, it also points to the possible use of CBM 8’s secure communications framework. Overall, it seeks to foster cooperation and transparency among states and stakeholders.

Practice: The Netherlands, Czechia, Hungary, and Romania have assumed responsibility as adopters of this CBM. One concrete measure has been the development of a publicly available e-learning course on CVD by the OSCE Secretariat’s TNTD. The course introduces CVD as a tool to strengthen cyber resilience, covering key actors, process steps, legal challenges, and concludes with a fictional scenario to illustrate practical application. Within this framework, the Netherlands share information on their national CVD guidelines, which assist companies and organizations in setting up their own policies. While such initiatives contribute to CBM implementation, they are also pursued independently of the OSCE framework, thus implicitly fulfilling the CBM’s objectives.

Workshops have also been organized to advance this CBM, such as the 2023 event in Istanbul, where good practices and examples of national implementation were presented and participants engaged in a practical exercise to better understand the nuances of vulnerability disclosure. These activities highlight growing engagement but also show that implementation remains limited in scope, overall, only a small number of states have national CVD policies in place. At present, the CBM can therefore be considered implemented, but not widely.

Key Implementation Activities and Resources

  • Participating states promote responsible vulnerability disclosure and share national experiences and good practices related to coordinated vulnerability disclosure frameworks.

  • Implementation is supported by OSCE e-learning courses, as well as practical workshops.