Linyang Energy places great emphasis on vulnerability management throughout the entire product lifecycle. In accordance with internationally recognized standards, including ISO/IEC 30111 and ISO/IEC 29147, we have established a comprehensive vulnerability response process to ensure that security vulnerabilities are addressed efficiently and promptly, thereby minimizing security risk to the greatest possible extent.
The security vulnerability response process comprises five core stages: (See reference design diagram)
1.Vulnerability Intake: Receiving security vulnerabilities submitted by all relevant parties
Linyang Energy encourages security practitioners, industry organizations, and partners worldwide to submit security vulnerabilities relating to the energy storage, smart-metering, and new-energy products of Jiangsu Linyang Energy Storage Technology Co., Ltd., Jiangsu Linyang Zhiwei Technology Co., Ltd., and Jiangsu Linyang New Energy Technology Co., Ltd. through the designated mailbox, psirt@linyang.com.cn. In parallel, the Linyang Energy PSIRT proactively monitors industry threat intelligence, identifies and records valid vulnerability information with precision, and builds a comprehensive vulnerability sourcing ecosystem with a focus on threat intelligence in the energy sector.
2. Risk Assessment: Validating the vulnerability, analyzing its impact, and evaluating the risk
The PSIRT conducts a comprehensive analysis and validation of each vulnerability report received to confirm its authenticity and reproducibility. In accordance with the CVSS 3.1 standard, the team assigns a severity classification and risk score to the vulnerability, which is then reviewed and confirmed by internal security experts, and ultimately determines the severity level and scope of impact of the vulnerability.
3. Vulnerability Disclosure: Maintaining communication with reporters and affected customers, assisting with remediation, and completing coordinated disclosure
Throughout the vulnerability response process, Linyang Energy maintains communication with customers and relevant parties and keeps them informed of handling progress. Following the validation of remediation solutions, security patches will be pushed to affected customers together with deployment guidance, to assist them in completing remediation at the earliest opportunity, with patch adoption tracked on an ongoing basis. Coordinated vulnerability disclosure is then completed, effectively reducing the risk of exploitation.
4. Continuous Improvement: Conducting post-incident reviews to continuously optimize processes and product security
Following the completion of vulnerability remediation, Linyang Energy conducts reviews from management, technical, and process perspectives to capture lessons learned and continuously optimize the vulnerability response process. Through these efforts, we enhance the security of our products and deliver more trustworthy security products and services to our customers.