House panel rips CVE contracting and oversight policies
Full article755 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The industry-wide program for naming and documenting vulnerabilities suffers from fluctuating funding and insufficient oversight, according to a House panel.
The industrywide program for documenting hardware and software vulnerabilities suffers from fluctuating funding and insufficient oversight, according to a more than yearlong investigation by the House Energy and Commerce Committee.
“The historical practices for managing the … program are clearly insufficient,” members of the committee wrote in letters Monday to the Department of Homeland Security, which sponsors the program, and the not-for-profit MITRE Corp., which maintains it. “Barring significant improvements, they will likely lead again to challenges that have direct, negative impacts on stakeholders across society.”
The program in question, the Common Vulnerabilities and Exposures (CVE) database, has for nearly two decades been a common lexicon for researchers and companies that document security flaws. But the program has experienced a significant backlog as some researchers have struggled to get a response to their submissions.
MITRE has undertaken reforms of the program, but House lawmakers say the “root causes” of the program’s woes – its lack of oversight and its reliance on piecemeal contracting – have “yet to be addressed.”
The lawmakers, which include committee Chairman Greg Walden, R-Ore., want DHS to give the CVE program a dedicated line item in the department’s annual budget rather than the haphazard funding they say the program currently receives. Over seven years, the contracting vehicle for the CVE program was awarded or modified 30 times, according to the House panel.
“Funding this key cybersecurity program through piecemeal, short-term contracts does it a disservice,” the committee members wrote. “The documentation provided by DHS and MITRE shows that the CVE contract vehicle is both unstable and prone to acute fluctuations in schedule and funding.”
In an effort to keep pace with cyberthreats, the lawmakers also want DHS and MITRE to conduct more rigorous oversight of the CVE program through biennial reviews. “The failure to conduct systematic reviews of the CVE program on a regular basis has allowed small problems to fester and morph into the kind of entrenched problems that the committee highlighted in its first letter” to the organizations in 2017, they wrote.
The lawmakers have requested briefings from DHS and MITRE on the CVE program within the next two weeks.
CyberScoop has requested comment from MITRE and will update this story if it is received.
You can read the full letters below.
[documentcloud url=”http://www.documentcloud.org/documents/4788036-082718-DHS-Recommendations-for-CVE-Program.html” responsive=true height=500]
[documentcloud url=”http://www.documentcloud.org/documents/4788035-082718-MITRE-Recommendations-for-CVE-Program-1.html” responsive=true height=500]
More Scoops
House intel bill includes provisions on state and local threat intelligence, election security, AI
The House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday.
Open-source security is posing challenges governments can’t easily solve
Hill Dems hammer GOP for $250M CISA budget cut
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cve-mitre-house-energy-and-commerce-committee/