Categories: US-Cert-Repository

CISA Releases Draft of Binding Operational Directive on Developing a Vulnerability Disclosure Policy



Original release date: December 2, 2019

The Cybersecurity and Infrastructure Security Agency (CISA) has released a draft of Binding Operational Directive (BOD) 20-01, Develop and Publish a Vulnerability Disclosure Policy. BOD 20-01 will require each federal agency to publish a vulnerability disclosure policy (VDP). CISA has posted the draft directive for public feedback. The deadline for submitting comments is 11:59 PM EST on December 27, 2019.
 
CISA encourages users and administrators to review the CISA blog post, Improving Vulnerability Disclosure Together, and draft BOD 20-01 for more information. CISA encourages feedback on draft BOD 20-01 from individuals with personal or institutional expertise in vulnerability disclosure and from organizations that have a VDP and manage coordinated vulnerability disclosures.

This product is provided subject to this Notification and this Privacy & Use policy.



Source link

admin

Share
Published by
admin

Recent Posts

Vulnerabilities in TCP

Systems Affected Systems that rely on persistent TCP connections, for example routers supporting BGP Overview…

2 days ago

CVS Heap Overflow Vulnerability

Systems Affected   Concurrent Versions System (CVS) versions prior to 1.11.16 CVS Features versions prior…

3 days ago

SQL Injection Vulnerabilities in Oracle E-Business Suite

Systems Affected Oracle Applications 11.0 (all releases) Oracle E-Business Suite 11i, 11.5.1 through 11.5.8 Overview…

4 days ago

Cross-Domain Vulnerability in Internet Explorer

Systems Affected   Microsoft Windows systems   Overview   Microsoft Internet Explorer (IE) contains a…

5 days ago

Cross-Domain Redirect Vulnerability in Internet Explorer

Systems Affected   Microsoft Windows systems   Overview   A cross-domain vulnerability in Internet Explorer…

6 days ago

This website uses cookies.