This document summarizes Larissa Shapiro's presentation on internet systems consortium's (ISC) vulnerability disclosure processes. The presentation discusses ISC's current vulnerability disclosure policy version 1.1 and planned updates for version 1.2. It also covers ISC's use of test driven development and how it impacts vulnerability disclosure. Key points include that ISC uses a phased disclosure process to balance responsibility to critical infrastructure with allowing time for upgrades. Future plans include expanding pre-disclosure notification and integrating vulnerability testing back into code at a future time defined in policy version 2.0.