A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD)

SEI Report
This report discusses performance indicators that stakeholders in Coordinated Vulnerability Disclosure (CVD) can use to measure its effectiveness.
Publisher

Software Engineering Institute

CMU/SEI Report Number
CMU/SEI-2021-SR-021
DOI (Digital Object Identifier)
10.1184/R1/16416771

Abstract

Coordinated Vulnerability Disclosure (CVD) stands as a consensus response to the persistent fact of vulnerable software, yet few performance indicators have been proposed to measure its efficacy at the broadest scales. In this report, we seek to fill that gap. We begin by deriving a model of all possible CVD histories from first principles, organizing those histories into a partial ordering based on a set of desired criteria. We then compute a baseline expectation for the frequency of each desired criteria and propose a new set of performance indicators to measure the efficacy of CVD practices based on the differentiation of skill and luck in observation data. As a proof of concept, we apply these indicators to a variety of longitudinal observations of CVD practice and find evidence of significant skill to be prevalent. We conclude with reflections on how this model and its accompanying performance indicators could be used by various stakeholders (vendors, system owners, coordinators, and governments) to interpret the quality of their CVD practices.

Cite This SEI Report

Householder, A., & Spring, J. (2021, July 1). A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD). (SEI Report CMU/SEI-2021-SR-021). Retrieved September 11, 2026, from https://doi.org/10.1184/R1/16416771.

@techreport{householder_2021,
author={Householder, Allen and Spring, Jonathan},
title={A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD)},
month={Jul},
year={2021},
number={{CMU/SEI-2021-SR-021},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/16416771},
url={https://doi.org/10.1184/R1/16416771},
note={Accessed: 2026-Sep-11}
}

Householder, Allen, and Jonathan Spring. "A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD)." (CMU/SEI-2021-SR-021). Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, July 1, 2021. https://doi.org/10.1184/R1/16416771.

A. Householder, and J. Spring, "A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD)," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, SEI Report CMU/SEI-2021-SR-021, 1-Jul-2021 [Online]. Available: https://doi.org/10.1184/R1/16416771. [Accessed: 11-Sep-2026].

Householder, Allen, and Jonathan Spring. "A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD)." (SEI Report CMU/SEI-2021-SR-021). Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Jul. 2021. https://doi.org/10.1184/R1/16416771. Accessed 11 Sep. 2026.

Householder, Allen; & Spring, Jonathan. A State-Based Model for Multi-Party Coordinated Vulnerability Disclosure (MPCVD). CMU/SEI-2021-SR-021. Software Engineering Institute. 2021. DOI: 10.1184/R1/16416771. https://doi.org/10.1184/R1/16416771