The Yokogawa Group Vulnerability Handling Policy

Purpose of the Policy

The purpose of this policy is to describe the Yokogawa Group's fundamental principles and processes for vulnerability handling to stakeholders, including customers, Computer Emergency Response Team (CERT) organizations (*1), vendors, and security researchers.
The Yokogawa Group addresses vulnerabilities in its products (*2) in accordance with this policy.
We sincerely appreciate the efforts of all stakeholders who work together with us to reduce cybersecurity risks and protect customer assets by identifying and addressing vulnerabilities that could be exploited by cyber threats.

 

Basic Policy

The Yokogawa Group recognizes that continuous assessment and mitigation of cybersecurity risks are critical aspects of protecting customer assets. We are committed to supporting our customers in maintaining the security of their environments.
As part of our vulnerability handling activities, we support our customers' risk management efforts by providing information about vulnerabilities affecting our products and by offering appropriate mitigation and remediation measures.

 

Process

The vulnerability handling process consists of the following steps:

1. Vulnerability Report Intake

The Yokogawa Group welcomes reports of vulnerabilities affecting its products.
In general, we will acknowledge receipt of a vulnerability report within one to two business days. We may contact the reporter to request additional information if necessary.
Please submit vulnerability reports through the following contact channel:
https://contact.yokogawa.com/cs/gw?c-id=000983

In accordance with the principles of Coordinated Vulnerability Disclosure (CVD) (*3), we request that anyone who discovers a vulnerability report it to the Yokogawa Group or an appropriate CERT organization before publicly disclosing the information.

 

2. Vulnerability Investigation

We investigate the potentially affected products and assess the impact of the reported vulnerability.
We will share the results of our investigation with the reporter, as appropriate. We also evaluate the severity of the vulnerability using the Common Vulnerability Scoring System (CVSS) (*4).

 

3. Remediation Preparation

Based on the assessed severity of the vulnerability, we evaluate and prepare appropriate measures, which may include:
- Remediation Measures: Patches, corrected versions, upgrades, or other solutions intended to eliminate or reduce the vulnerability.
- Mitigation Measures: Recommended actions that help reduce the risk or impact of attacks exploiting the vulnerability.

 

4. Advisory Publication

We provide customers with a security advisory, referred to as a YSAR (Yokogawa Security Advisory Report), containing information about the vulnerability.
Prior to publication, we coordinate with the reporter and/or relevant CERT organizations, as appropriate, regarding the content and timing of the advisory.
- Details of the Advisory
    An advisory typically includes the following information:
    - Description of the vulnerability
    - Affected products and versions
    - CVE ID
    - Severity rating (CVSS score)
    - Remediation or mitigation measures
    - Acknowledgments (with the reporter's consent)
    - Contact information
- Advisory Distribution
    An advisory is distributed through one or more of the following channels:
    - Yokogawa Group website

    - Customer notifications provided in accordance with applicable product maintenance or support service agreements
- Advisory Publication Timing
    As a general rule, vulnerability information is disclosed after remediations have been prepared and are ready for deployment.
However, if active exploitation is observed or if prompt customer notification is deemed necessary to protect customer assets, we may consider publishing an advisory once appropriate mitigations have been prepared, even before a full remediation becomes available.

 

CVE ID

As a CVE Numbering Authority (CNA) (*5), the Yokogawa Group assigns CVE IDs to vulnerabilities affecting its products.

 

To Vulnerability Reporters

With the reporter's consent, we may acknowledge the reporter in the relevant security advisory.


(*1) CERT (Computer Emergency Response Team)
 Organizations that receive, coordinate, publish, and provide alerts regarding vulnerability information and cybersecurity incidents. Examples include JPCERT/CC, CERT/CC, and CISA.
(*2) Yokogawa Products
https://www.yokogawa.com/solutions/products-and-services/
(*3) Coordinated Vulnerability Disclosure (CVD)
 A vulnerability disclosure practice that prioritizes the protection of users by encouraging discoverers to report vulnerabilities privately to vendors and/or CERT organizations before public disclosure, thereby allowing appropriate remediation measures to be prepared.
Reference: https://www.cisa.gov/resources-tools/programs/coordinated-vulnerability-disclosure-program
(*4) Common Vulnerability Scoring System (CVSS)
 An industry-standard framework for communicating the severity of software and hardware vulnerabilities using a numeric score ranging from 0.0 to 10.0.
Reference: https://www.first.org/cvss/
(*5) About the CVE Program
https://www.cve.org/About/Overview


 

Contact for Inquiries

For inquiries concerning the handling of vulnerabilities, please contact us at the following address.
https://contact.yokogawa.com/cs/gw?c-id=000498

 

Revision History

November 20, 2018: Established
October 25, 2023: Added "CVE ID" section
August 6, 2026: Updated "4. Advisory Publication" section

News

Looking for more information on our people, technology and solutions?

Contact Us

Top