CISA orders agencies to set up vulnerability disclosure programs
Full article772 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It’s the latest sign that federal officials are warming to white-hat hackers from various walks of life.
Out of scores of federal civilian agencies, only a handful of them have official programs to work with outside security researchers to find and fix software bugs — a process that is commonplace in the private sector.
Now, to put an end to the feet-dragging, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency is giving agencies six months to set up the programs, known as vulnerability disclosure policies (VDPs).
CISA on Wednesday issued a directive requiring agencies to establish VDPs that foreswear legal action against researchers who act in good faith, allow participants to submit vulnerability reports anonymously and cover at least one internet-accessible system or service. It’s the latest sign that federal officials are warming to white-hat hackers from various walks of life.
“We believe that better security of government computer systems can only be realized when the people are given the opportunity to help,” CISA Assistant Director Bryan S. Ware said in announcing the directive.
The White House echoed that language in a memo to agencies backing the VDP initiative and setting deadlines for agencies to act.
“By clearly providing reporting mechanisms, timely feedback, and remediation, agencies can benefit from good-faith security research to enhance the security of federal information systems,” the Office of Management and Budget memo says.
Federal progress on VDPs has been slow. Very few federal civilian agencies have adopted programs in the 10 months since CyberScoop reported that CISA was considering issuing the directive.
Agencies will have to gradually add systems to their VDPs until, after two years, all of an agency’s internet-accessible assets are covered by the program. CISA will be helping agencies with limited resources and experience set up VDPs, Ware said.
Lawmakers welcomed the directive.
“CISA deserves praise for this effort to repair the damage done over the years by government agencies harassing and prosecuting cybersecurity researchers,” said Sen. Ron Wyden, D-Ore. “Americans are better off if the first person to find a security problem in [a] government system is a researcher working in the public interest, who will report the flaw so it can be fixed, and not a hacker working for Russia or China.”
Rep. Jim Langevin, D-R.I., co-founder of the Congressional Cybersecurity Caucus, suggested that states and local governments, and even private firms, could use the CISA directive as a blueprint for working with researchers.
The effort to adopt VDPs at the federal level coincides with a gradual embrace of them in the election infrastructure sector. In August, Ohio became the first state to issue a VDP for election-related websites. That same week, the largest voting equipment vendor in the U.S. announced its own VDP.
More Scoops
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech.
CISA directive orders agencies to prioritize vulnerability patching in a new way
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-vulnerability-disclosure-directive-omb/