Policy Center

Product Cybersecurity Vulnerability Management Policy

BenQ is committed to perfecting the product cybersecurity vulnerability reporting process and providing customers with reliable guidelines and solutions (or mitigation measures) for product cybersecurity vulnerabilities.

.

.

(A) Introduction

 

BenQ is committed to perfecting the product cybersecurity vulnerability reporting process and providing customers with reliable guidelines and solutions (or mitigation measures) for product cybersecurity vulnerabilities to minimise the associated risks. To achieve this, BenQ has established a Product Cybersecurity Vulnerability Reporting Team responsible for handling matters related to product cybersecurity vulnerabilities reported to BenQ.

 

The BenQ Product Security Incident Response Team (BenQ PSIRT) will continuously reference internationally and industry-wide accepted practices, regulations, and standards to consistently strengthen product cybersecurity vulnerability handling procedures and measures. Furthermore, this policy ensures that BenQ employees share a consistent and clear methodology for handling vulnerability reports and understand how to properly respond to such incidents.

 

BenQ agrees not to pursue legal action relating to a vulnerability report and the associated security research against a reporting individual that complies with these rules.

.

(B) Scope

 

This Product Cybersecurity Vulnerability Management Policy applies to product-related cybersecurity vulnerabilities reported about BenQ products with digital elements that are made available on the market. For non-standard or customised products, vulnerabilities will be handled in accordance with the terms of the respective agreements (contracts).

.

(C) How to Report a Cybersecurity Vulnerability

 

If you discover a potential cybersecurity vulnerability in our products, please submit a vulnerability report through our Product Cybersecurity Vulnerability Reporting website. We will verify your report and, if necessary, contact you for more information. PSIRT will not be able to process the report if the submitted vulnerability information is incomplete, incorrect, duplicated, or false.

You are required to cooperate with any requests by BenQ for additional information, assistance, research, and you agree to coordinate disclosures of any vulnerability as noted herein. If no response is received from you within 30 calendar days of our last inquiry, BenQ reserves the right to close the case.

When reporting a potential vulnerability, you will be asked to include the following information as much as possible to help us clearly understand the nature and scope of the reported issue.

 

  • Product type / model name
  • Product name
  • Software / Firmware version
  • Vulnerability description
  • Step-by-step instruction to reproduce the issue
  • Common Weakness Enumeration (CWE) ID
  • Common Vulnerabilities and Exposures (CVE) ID
  • CVSS Score
  • CVSS Vector String

.

(D) Product Cybersecurity Vulnerability Management Process

 

BenQ's product cybersecurity vulnerability management process consists of the following five stages:

 

1

Acknowledge Receipt

After receiving an external vulnerability report regarding BenQ products, BenQ PSIRT typically provides an initial response to the reporter within 2 working days (GMT+8).

2

Triage and Assessment

BenQ PSIRT categorises and analyses the potential cybersecurity vulnerability to conduct a preliminary assessment of its impact on BenQ products.

3

Investigation

BenQ PSIRT collaborates with the product development department to identify the root cause of the vulnerability and further evaluate its impact on BenQ products.

4

Mitigation

BenQ PSIRT will collaborate with the product development department to develop software/firmware patches or mitigation measures.

5

Disclosure

BenQ PSIRT will publish the results of the product cybersecurity vulnerability in the Product Cybersecurity Advisory on the BenQ website.

 

If BenQ determines that a report does not identify a vulnerability or that the reported vulnerability is a duplicate of a previously reported vulnerability, BenQ will notify the reporting individual of its determination and close the case. BenQ retains sole discretion to determine the validity, severity, and priority of any reported vulnerability, and the necessity and scope of any further response or action. 

.

(E) Disclosure Coordination

 

You may not disclose any potential vulnerability reported prior to the issuance of an associated Security Notification or Version Release Notes. If the vulnerability is expected to impact other vendors, then BenQ PSIRT can engage an external coordinator to coordinate public release of advisories and facilitate collaboration among the participating entities.

 

After such coordinated disclosure, you may further disclose or publicise your role in identifying the vulnerability but may not disclose further details about your engagement with BENQ (including emails), the vulnerability, or associated exploit steps without the express prior written consent of BenQ.

 

The time required for handling, including Mitigation and Disclosure, may be impacted by the relative criticality of the vulnerability and other relevant factors.

.

(F) Other Provisions

 

By submitting a vulnerability report to BenQ, you grant BenQ a non-exclusive, worldwide, irrevocable, perpetual, sub-licensable, royalty-free license to any intellectual property contained in that report or any follow-up communications related to the report to analyse, commercialise, publicise, disclose, or otherwise use such intellectual property in any manner. Participating in this process does not give you any right to any intellectual property of BenQ.

 

BenQ reserves the right to change these terms at any time and without advance notice. Continued participation in this process after a change in terms constitutes acceptance of the amended terms.

 

TOP