Hikvision Achieves Essential Cybersecurity Certifications
Hikvision, the leading provider of innovative video surveillance products, has made significant strides in vulnerability management by achieving ISO/IEC 29147 and ISO/IEC 30111 certifications. Awarded by the British Standards Institution (BSI), these certifications confirm that Hikvision's practices are in accordance with internationally recognized standards, reinforcing their commitment to security in technology development.
Understanding ISO/IEC 29147 and ISO/IEC 30111
These two standards were jointly developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). They offer a well-structured framework for managing vulnerabilities throughout the product lifecycle. Specifically, ISO/IEC 29147 establishes a uniform approach for receiving vulnerability reports from external sources, while ISO/IEC 30111 lays out internal processes for investigating and addressing those vulnerabilities effectively.
ISO/IEC 29147:2018
ISO/IEC 29147:2018 focuses on creating transparency in how organizations handle vulnerability reports. It ensures that organizations maintain clear communication with external researchers and the public, which is essential for swift and effective vulnerability management.
ISO/IEC 30111:2019
The purpose of ISO/IEC 30111:2019 is to guide organizations in developing internal engineering processes. This helps ensure that vulnerabilities are investigated, analyzed, and resolved in a systematic way that promotes accountability and thoroughness.
Enhancing Global Cybersecurity Trust
The BSI audit revealed Hikvision's unwavering dedication to enhancing its cybersecurity governance and vulnerability management framework. By adhering to these certifications, Hikvision can:
- Establish a clear and traceable process for assessing and responding to vulnerabilities.
- Utilize advanced automated tools that increase the efficiency and accuracy of its vulnerability management.
- Minimize risks to users while bolstering trust among partners and consumers by providing secure products.
This certification is timely, especially as global regulations concerning cybersecurity continue to tighten. Hikvision's procedures meet rigorous international standards, including the European Union's Cyber Resilience Act, which demands robust vulnerability disclosure and remediation throughout the lifecycle of connected products.
Commitment to Proactive Vulnerability Management
Hikvision has long positioned security as a fundamental part of its product development and corporate ethos. In recent years, the company has undertaken several initiatives to strengthen its security posture:
- In 2014, the company launched the Hikvision Security Response Center (HSRC), a dedicated entity for managing the reporting and disclosure of security vulnerabilities.
- By 2018, Hikvision became a recognized CVE CNA, collaborating with global security researchers to efficiently identify and resolve vulnerabilities.
- Most recently, in 2023, Hikvision opened its CyberSafe Experience Center in the Netherlands. This center not only conducts regular vulnerability assessments on products but also educates partners and visitors about its commitment to security.
Throughout the past decade, the evolution of Hikvision's vulnerability handling processes has not only focused on compliance with international regulations but also on leveraging technology to enhance efficiency and security. By implementing the ISO/IEC 29147 and ISO/IEC 30111 frameworks, Hikvision strives to continually refine these practices and encourage collaboration with the global security research community.
In conclusion, Hikvision's dedication to providing secure and reliable video surveillance solutions positions them as a leader in the industry. Their proactive measures and adherence to recognized standards underline the commitment to cybersecurity, ensuring peace of mind for customers globally.
Frequently Asked Questions
What certifications has Hikvision achieved?
Hikvision has achieved ISO/IEC 29147 and ISO/IEC 30111 certifications for their vulnerability management practices.
Why are ISO/IEC 29147 and ISO/IEC 30111 important?
These standards help ensure that organizations manage vulnerabilities systematically and transparently, enhancing accountability and security.
How does Hikvision handle vulnerability reports?
Hikvision has established a structured process for receiving and addressing vulnerability reports from external sources, enhancing communication and responsiveness.
What is the role of the Hikvision Security Response Center?
The Hikvision Security Response Center (HSRC) is responsible for managing the receipt, processing, and disclosure of security vulnerabilities globally.
How does Hikvision collaborate with security researchers?
Hikvision collaborates with security researchers worldwide to identify, address, and publicly disclose vulnerabilities, reinforcing their commitment to responsible disclosure practices.