NeuroCheck Product Security Incident Response Team (PSIRT)
The Product Security Incident Response Team (PSIRT) at NeuroCheck is the central organizational function responsible for the management of product vulnerabilities.
The PSIRT coordinates the intake, assessment, handling, and communication of reported or internally identified product vulnerabilities. Its goal is to systematically assess potential security risks, coordinate appropriate remediation measures, and ensure appropriate and traceable handling throughout the entire support period of the affected products and systems.
PSIRT Responsibilities
The NeuroCheck PSIRT coordinates, in particular:
- the intake and recording of product vulnerabilities,
- the assessment and prioritization of potential security risks,
- the analysis and handling of confirmed product vulnerabilities,
- the development, timely implementation, and provision of appropriate remediation measures,
- the internal and external communication regarding product vulnerabilities, and
- the coordinated disclosure of confirmed product vulnerabilities (Coordinated Vulnerability Disclosure, CVD).
Depending on the nature and scope of a product vulnerability, the PSIRT involves the required specialist departments and, where appropriate, external parties in the analysis and implementation of suitable remediation measures.
Our Principles
When handling product vulnerabilities, the NeuroCheck PSIRT follows consistent principles.
Information about reported or internally identified product vulnerabilities is treated as confidential until an agreed disclosure. Product vulnerabilities are assessed based on risk and prioritized according to their potential impact. Handling is coordinated across the departments involved and documented in a traceable manner.
We appropriately communicate relevant information about confirmed product vulnerabilities and available remediation measures to affected customers and other relevant stakeholders. We aim to coordinate the disclosure of confirmed product vulnerabilities with the parties involved in accordance with the principles of Coordinated Vulnerability Disclosure (CVD).
Scope
The Product Security Incident Response Team (PSIRT) is responsible for the management of product vulnerabilities in products and systems for which NeuroCheck is responsible during their support period. This includes, in particular, our software products, industrial PCs, and machine vision systems.
For products or components from other manufacturers that are distributed by NeuroCheck or integrated into NeuroCheck systems, the PSIRT coordinates the measures required on the NeuroCheck side. Responsibility for analyzing and remediating the vulnerability in the third-party product remains with the respective manufacturer.
Reporting a Product Vulnerability
If you have discovered a potential product vulnerability in a NeuroCheck product, please refer to our Vulnerability Disclosure Policy (VDP) for information on the reporting procedure and the required information.
Copyright notice for the photos used on this page:
Header image © NeuroCheck
