Hikvision has received certification from the British Standards Institution (BSI) for ISO/IEC 29147:2018 and ISO/IEC 30111:2019, signifying alignment with international standards in vulnerability management.
These certifications affirm Hikvision’s commitment to maintaining high cybersecurity standards through effective vulnerability management practices.
International Vulnerability Management Framework
The certification standards ISO/IEC 29147 and ISO/IEC 30111, developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), offer a comprehensive framework for managing vulnerabilities throughout the product lifecycle.
ISO/IEC 29147:2018 focuses on the external communication of vulnerabilities, ensuring companies standardize the process of receiving and disclosing vulnerability reports from external sources. Meanwhile, ISO/IEC 30111:2019 details internal processes for investigating and resolving vulnerabilities within organizations.
Commitment to Robust Cybersecurity Practices
Hikvision showcases its structured approach to managing security flaws
A recent audit by the BSI underscored Hikvision’s dedication to maintaining strong cybersecurity governance.
With these standards, Hikvision showcases its structured approach to managing security flaws, using automated tools to enhance efficiency, and ultimately ensuring user protection and supply chain trust. The certification aligns with evolving global regulations, including the European Union's Cyber Resilience Act (CRA), which demands rigorous vulnerability management practices.
Evolving Security Strategies
Security has been a critical focus for Hikvision, guiding both product development and corporate strategy. In 2014, the company created the Hikvision Security Response Center (HSRC) to streamline the process of managing global security vulnerabilities.
By 2018, Hikvision became a CVE CNA, collaborating with worldwide security researchers to address vulnerabilities efficiently. The establishment of the CyberSafe Experience Center in Hoofddorp, the Netherlands, in 2023 reflects the company’s proactive approach to security, enabling ongoing vulnerability assessments and increasing transparency for customers.
Advancing Vulnerability Management
Hikvision has consistently improved its vulnerability management system over the last decade to align with global regulatory standards and enhance security response through automation.
By integrating ISO/IEC 29147 and ISO/IEC 30111 frameworks, Hikvision not only complies with these standards but also continues to foster global collaboration with security researchers. The company's commitment ensures the delivery of secure, reliable intelligent products worldwide.
Hikvision announced it has been awarded ISO/IEC 29147:2018 and ISO/IEC 30111:2019 certification by the British Standards Institution (BSI), a globally recognized standards and certification body. The achievement endorses that Hikvision’s vulnerability management practices aligns with the international standards.
Jointly developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), ISO/IEC 29147 and ISO/IEC 30111 provide a structured framework for vulnerability management across the full product lifecycle.
Internal engineering processes
ISO/IEC 29147:2018 defines the external interface of vulnerability management. It standardises how organizations receive vulnerability reports from external researchers and how they communicate and disclose information to the public, ensuring the process is timely and transparent.
ISO/IEC 30111:2019 specifies internal engineering processes for the investigation, analysis, remediation, and verification of reported vulnerabilities to ensure effective resolution.
Robust vulnerability management
The BSI audit highlighted Hikvision’s ongoing commitment to robust vulnerability management and cybersecurity governance. By aligning with these standards, Hikvision demonstrates its ability to:
- Operate a structured and traceable mechanism for receiving, assessing, and responding to security weaknesses.
- Utilize automated tools to enhance the speed and accuracy of vulnerability processing.
- Reduce user risks and enhance trust across the global supply chain by delivering secure products and services
This certification comes at a pivotal time as global regulatory expectations evolve. Hikvision’s certified procedures comply with stringent international requirements, including the European Union’s Cyber Resilience Act (CRA), which mandates robust vulnerability disclosure and remediation practices throughout the lifecycle of connected products.
Responsible disclosure practices
Hikvision has long prioritised security as a core element of its product development and corporate strategy.
- In 2014, the company established the Hikvision Security Response Center (HSRC) to manage the receipt, processing, and disclosure of security vulnerabilities globally.
- In 2018, Hikvision became a CVE CNA (CVE Partner) working closely with security researchers worldwide to rapidly identify, patch and publicly disclose vulnerabilities as part of its responsible disclosure practices.
- In 2023, Hikvision opened its CyberSafe Experience Center in Hoofddorp, the Netherlands, where it conducts regular vulnerability scans on its products and offers customers, partners, and visitors clear insight into its vulnerability management practices.
Vulnerability management practices
Over the past decade, the company has continued to mature its vulnerability handling system to not only support compliance with global regulatory requirements, but also leverage automation to improve response efficiency and product security.
By implementing the ISO/IEC 29147 and ISO/IEC 30111 frameworks, Hikvision continues to optimize this system, deepening its collaboration with the global community of security researchers. Hikvision remains dedicated to delivering secure, reliable intelligent products and solutions to customers worldwide.