Security Incident Response(new)

Product Security Incident Response Center

Sungrow places great importance on the remediation of security vulnerabilities. The Sungrow Product Security Incident Response Team (PSIRT) spearheads the company’s Vulnerability Disclosure Program (VDP), responsible for the intake, investigation, internal coordination, and disclosure of security vulnerability information associated with Sungrow’s products and services.

Full-lifecycle Vulnerability Governance per International Norms
ISO/IEC 29147
ISO/IEC 30111
CRA
Sungrow's PSIRT team follows the principles and practices defined in ISO/IEC 29147 (Vulnerability Disclosure), ISO/IEC 30111 (Vulnerability Handling Processes), and aligns with applicable requirements of the EU CRA, to ensure effective, timely, and compliant vulnerability handling.
Security Incident Response(new)

Reception

Sungrow continuously identifies potential vulnerabilities through multiple channels, including reports from security researchers, customers, partners, and suppliers, as well as proactive threat intelligence detection.
● Dedicated security email:psirt@sungrowpower.com
● Official PSIRT Portal:https://cn.sungrowpower.com/en/security-incident-response
● Dedicated reporting channel
● Proactive threat intelligence monitoring

Assessment

● Validation:Verify the authenticity and reproducibility of the reported vulnerability
● Impact Analysis: Assess affected products, versions, and customer impact
● Risk Rating:Evaluate severity using CVSS methodology
● Prioritization:Determine remediation priority and response plan

Remediation

● Develop remediation plans
● Provide temporary mitigation measures when applicable
● Develop and test security patches
● Validate remediation effectiveness
● Prepare customer deployment guidance

Disclosure

Transparent Communication Framework
● Maintain continuous communication with vulnerability submitters and provide regular progress updates throughout remediation.
● Issue timely security advisories to all affected customers.
● Support customers with remediation planning and relevant technical assistance.
● Execute coordinated public disclosure after patches and fixes are fully ready.
Coordinated Disclosure Principles
● Vulnerability details will not be publicly disclosed until remediation is available.
● Disclosure timing is coordinated with the reporting party.
● Customers are provided with sufficient time to deploy mitigations and updates.

Improvement

Sungrow conducts regular vulnerability reviews and improvement initiatives, carrying out technical and procedural reviews to identify root causes and define corrective actions. Lessons learned from these activities are incorporated into our secure development processes, product security controls and vulnerability response framework, enabling continuous enhancement of our security defense capabilities.

Homeowners
Business Owners
Large Scale
Partners
Products
Service & Support
Sustainability
About Us
© 2023 SUNGROW. All Rights Reserved.
chatbotchatbot