Purpose of the Policy
The purpose of this policy is to describe the Yokogawa Group's fundamental principles and processes for vulnerability handling to stakeholders, including customers, Computer Emergency Response Team (CERT) organizations (*1), vendors, and security researchers.
The Yokogawa Group addresses vulnerabilities in its products (*2) in accordance with this policy.
We sincerely appreciate the efforts of all stakeholders who work together with us to reduce cybersecurity risks and protect customer assets by identifying and addressing vulnerabilities that could be exploited by cyber threats.
Basic Policy
The Yokogawa Group recognizes that continuous assessment and mitigation of cybersecurity risks are critical aspects of protecting customer assets. We are committed to supporting our customers in maintaining the security of their environments.
As part of our vulnerability handling activities, we support our customers' risk management efforts by providing information about vulnerabilities affecting our products and by offering appropriate mitigation and remediation measures.
Process
The vulnerability handling process consists of the following steps:
1. Vulnerability Report Intake
The Yokogawa Group welcomes reports of vulnerabilities affecting its products.
In general, we will acknowledge receipt of a vulnerability report within one to two business days. We may contact the reporter to request additional information if necessary.
Please submit vulnerability reports through the following contact channel:
https://contact.yokogawa.com/cs/gw?c-id=000983
In accordance with the principles of Coordinated Vulnerability Disclosure (CVD) (*3), we request that anyone who discovers a vulnerability report it to the Yokogawa Group or an appropriate CERT organization before publicly disclosing the information.
2. Vulnerability Investigation
We investigate the potentially affected products and assess the impact of the reported vulnerability.
We will share the results of our investigation with the reporter, as appropriate. We also evaluate the severity of the vulnerability using the Common Vulnerability Scoring System (CVSS) (*4).
3. Remediation Preparation
Based on the assessed severity of the vulnerability, we evaluate and prepare appropriate measures, which may include:
- Remediation Measures: Patches, corrected versions, upgrades, or other solutions intended to eliminate or reduce the vulnerability.
- Mitigation Measures: Recommended actions that help reduce the risk or impact of attacks exploiting the vulnerability.
4. Advisory Publication
We provide customers with a security advisory, referred to as a YSAR (Yokogawa Security Advisory Report), containing information about the vulnerability.
Prior to publication, we coordinate with the reporter and/or relevant CERT organizations, as appropriate, regarding the content and timing of the advisory.
- Details of the Advisory
An advisory typically includes the following information:
- Description of the vulnerability
- Affected products and versions
- CVE ID
- Severity rating (CVSS score)
- Remediation or mitigation measures
- Acknowledgments (with the reporter's consent)
- Contact information
- Advisory Distribution
An advisory is distributed through one or more of the following channels:
- Yokogawa Group website
- Customer notifications provided in accordance with applicable product maintenance or support service agreements
- Advisory Publication Timing
As a general rule, vulnerability information is disclosed after remediations have been prepared and are ready for deployment.
However, if active exploitation is observed or if prompt customer notification is deemed necessary to protect customer assets, we may consider publishing an advisory once appropriate mitigations have been prepared, even before a full remediation becomes available.
CVE ID
As a CVE Numbering Authority (CNA) (*5), the Yokogawa Group assigns CVE IDs to vulnerabilities affecting its products.
To Vulnerability Reporters
With the reporter's consent, we may acknowledge the reporter in the relevant security advisory.
(*1) CERT (Computer Emergency Response Team)
Organizations that receive, coordinate, publish, and provide alerts regarding vulnerability information and cybersecurity incidents. Examples include JPCERT/CC, CERT/CC, and CISA.
(*2) Yokogawa Products
https://www.yokogawa.com/solutions/products-and-services/
(*3) Coordinated Vulnerability Disclosure (CVD)
A vulnerability disclosure practice that prioritizes the protection of users by encouraging discoverers to report vulnerabilities privately to vendors and/or CERT organizations before public disclosure, thereby allowing appropriate remediation measures to be prepared.
Reference: https://www.cisa.gov/resources-tools/programs/coordinated-vulnerability-disclosure-program
(*4) Common Vulnerability Scoring System (CVSS)
An industry-standard framework for communicating the severity of software and hardware vulnerabilities using a numeric score ranging from 0.0 to 10.0.
Reference: https://www.first.org/cvss/
(*5) About the CVE Program
https://www.cve.org/About/Overview
Contact for Inquiries
For inquiries concerning the handling of vulnerabilities, please contact us at the following address.
https://contact.yokogawa.com/cs/gw?c-id=000498
Revision History
November 20, 2018: Established
October 25, 2023: Added "CVE ID" section
August 6, 2026: Updated "4. Advisory Publication" section
News
Looking for more information on our people, technology and solutions?
Contact Us