Title: Bug Bounty Vs Vulnerability Disclosure Programs
1Bug Bounty
learntorise
Vulnerability Disclosure Programs
_at_infosectrain
2Bug Bounty
www.infosectrain.com
learntorise
A Bug Bounty is a cash incentive given to Ethical
Hackers for identifying bugs.
VDPs A Vulnerability Disclosure Program (VDP) is
a standardized means for third parties, researcher
s, and Ethical Hackers to identify flaws
correctly.
_at_infosectrain
3Bug Bounty
www.infosectrain.com
learntorise
Bounty schemes often have predefined targets,
reward tiers, and SLA (Service Level Agreement)
times.
VDPs VDPs enable firms to define a broader scope
with more research resources to determine
and report on.
_at_infosectrain
4Bug Bounty
www.infosectrain.com
learntorise
The Bug Bounty Program enables firms to have a
broad, skilled team of ethical hackers regularly
detecting and resolving vulnerabilities.
VDPs VDPs provide a similar platform for
disclosure but often do not receive as much
interest, partly because they do not pay out
bounties.
_at_infosectrain
5sales_at_infosectain.com