Vendor Responsiveness
Vendor responsiveness is measured by the proportion of vulnerabilities that remains unconfirmed by the vendor and, therefore, unpatched over time.
Vendor responsiveness is an important security consideration because, in many cases, unsanctioned, unsupported and unmaintained software may be deployed within the organization. In the second half of 2006, 68% of documented vulnerabilities were not confirmed by the affected vendor. This is an increase from the first half of the year, when 61% of vulnerabilities were not confirmed by the vendor. In the second half of 2005, 55% of documented vulnerabilities were not vendor confirmed.

Source: Symantec Internet Security Threat Report, Vol. XI
|