A defined process for receiving, assessing, and acting on reports of security weaknesses from researchers or the public.
A vulnerability disclosure policy gives external finders a safe, clear way to report security weaknesses so they can be fixed before they are exploited. It sets expectations on scope, communication, and timelines for both sides.
Coordinated disclosure is increasingly expected by regulation, and standards encourage it as part of responsible product and service security. It complements internal scanning and penetration testing.