RCCE Course
Course #1063

Coordinated Vulnerability Disclosure and VDP Programs

📊 Level: Intermediate
⏱️ Duration: 2 Days
🏷️ Track: AppSec
📋 Prerequisites: Foundations
🖥️ Mode: Online Instructor-Led
📝 Course Description

RCCE students will learn how organizations receive, validate, prioritize, and disclose externally reported vulnerabilities through structured vulnerability disclosure and researcher engagement programs. RCCE students will learn to draft intake policies, define safe harbor language, manage disclosure timelines, coordinate remediation, work respectfully with researchers, and publish accurate public advisories without increasing risk unnecessarily. The course covers practical scenarios ranging from report intake through validation, disclosure coordination, and public communication. RCCE students will learn to analyze complex systems and think like an attacker to better defend the organization. This comprehensive course delivers practical knowledge applicable to real-world cybersecurity operations. Starting from foundational concepts, RCCE students will learn through a combination of concept explanation, practical demonstration, and hands-on exercises.

🎯 Target Audience
  • Security Engineers building defensive controls
  • Security Analysts and Blue Team members
  • Systems Administrators with security responsibilities
  • GRC and Risk Professionals supporting controls
  • Professionals implementing Coordinated Vulnerability Disclosure and VDP Programs
🧠 What You Will Learn
  • Execute hands-on tasks for coordinated vulnerability disclosure
  • Explain Course Overview fundamentals
  • Execute hands-on tasks for what you will learn
  • Execute hands-on tasks for course structure — covering Level: Intermediate — AppSec domain.
  • Execute hands-on tasks for why coordinated disclosure matters
  • Execute hands-on tasks for uncoordinated risks
  • Execute hands-on tasks for coordinated benefits — covering Controlled remediation timelines.
  • Execute hands-on tasks for first psirt services framework
  • Execute hands-on tasks for bug bounty
  • Execute hands-on tasks for full disclosure — covering Open to all security researchers, Reward-based incentive model.
  • Execute hands-on tasks for iso 29147 — disclosure — covering Defines how vendors receive reports, Establishes communication protocols.
  • Execute hands-on tasks for iso 30111 — handling — covering Internal vulnerability handling process, Triage, analysis, remediation phases.
📚 Course Outline
Module 01Coordinated Vulnerability Disclosure
Module 02Course Overview
Module 03What You Will Learn
Module 04Course Structure
Module 05Why Coordinated Disclosure Matters
Module 06Uncoordinated Risks
Module 07Coordinated Benefits
Module 08FIRST PSIRT Services Framework
Module 09Bug Bounty
Module 10Full Disclosure
Module 11ISO 29147 — Disclosure
Module 12ISO 30111 — Handling
Module 13Integration Point
Module 14VDP Policy Design Principles
🧪 Lab Details

All hands-on labs run on Rocheston Rose X OS. Students practice coordinated vulnerability disclosure and vdp programs by implementing the controls discussed in class, with a focus on real-world deployment, monitoring, and validation.

  • Lab 1: Execute hands-on tasks for coordinated vulnerability disclosure
  • Lab 2: Explain Course Overview fundamentals
  • Lab 3: Execute hands-on tasks for what you will learn
  • Lab 4: Execute hands-on tasks for course structure
  • Lab 5: Execute hands-on tasks for why coordinated disclosure matters
📊 Skill Level
Intermediate
Beginner Intermediate Advanced Expert
Duration
2 Days
🎓
Certificate
Completion
🖥️
Lab Platform
Rose X OS
👨‍🏫
Mode of Training
Online Instructor-Led
🔥
Platform
Zelfire
🐦‍⬛
Cyber Range
Raven
📓
Study Material
CyberNotes
🏆 Certificate

Upon successful completion of this course, students will receive an official RCCE Course Completion Certificate for Coordinated Vulnerability Disclosure and VDP Programs, verifiable through the Rocheston certification portal.

🔑 Student Access & Materials
  • Full access to all course materials and slide decks
  • Hands-on lab access on Rocheston Rose X OS environment
  • Access to Rocheston CyberNotes
  • Access to Rocheston Zelfire — EDR/XDR SIEM platform
  • Access to Rocheston Raven — online cyber range exercise platform
  • Access to Rocheston Vulnerability Vines AI