Jinko ESS encourages security researchers, industry organisations, customers and suppliers to report suspected vulnerabilities related to Jinko ESS products to the Jinko ESS PSIRT. The PSIRT will handle these reports in accordance with industry standards such as ISO/IEC 30111 and ISO/IEC 29147.
The security vulnerability response process consists of five stages:
1、Vulnerability awareness: receiving security vulnerabilities submitted by various parties.
Jinko ESS encourages global security practitioners and industry organisations to submit security vulnerabilities in Jinko ESS products. At the same time, the Jinko ESS PSIRT proactively acquires threat intelligence published by the industry to identify valid vulnerability information.
2、Vulnerability verification and assessment: confirming the validity and impact scope of suspected vulnerabilities.
The PSIRT analyses and verifies security vulnerabilities, follows the CVSS standard to rate and score product security vulnerabilities, and relevant security experts review and confirm the assessment results to determine the final evaluation.
3、Vulnerability remediation: providing mitigation measures and solutions after confirming that a product is affected by a vulnerability.
For confirmed security vulnerabilities, the Jinko ESS PSIRT works with the product team to develop and deliver fix plans (including mitigation measures and solutions), effectively responding to and resolving security risks, and ensuring the security and stability of customer data and systems.
4、Vulnerability disclosure: communicating with vulnerability reporters and affected customers, assisting customers in fixing vulnerabilities, and completing coordinated vulnerability disclosure.
Throughout the vulnerability response process, Jinko ESS maintains communication with customers and relevant parties, synchronises handling progress, assists customers in fixing vulnerabilities as early as possible, and completes coordinated vulnerability disclosure.
5、Closed-loop improvement: summarising improvements from management, technical and other dimensions to enhance the efficiency and quality of vulnerability handling.
For every security vulnerability, Jinko ESS conducts management and technical root-cause analysis, draws lessons, and continuously optimises the vulnerability response process, improves product security, and delivers secure and trustworthy products and services to customers.