Cybersecurity, Privacy, & AI

Trending Now
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts • CISA Guidance Targets Water Sector Security, Open Source AI and More • Salesforce Previews Plans to Deliver Newly Authorized ‘AI Agents’ Across DOD • CMS Pivots to Risk-Based Cybersecurity Model, CISO Says • Senate Set to Debate Package of Bills on Privacy, AI and Kids Safety

DHS is Mulling an Order that Would Force Agencies to Set Up Vulnerability Disclosure Programs

LeoWolfert | Shutterstock

DHS officials are mulling the release of a Binding Operational Directive to compel civilian federal agencies to get their security houses in order, typically on a tight deadline. The move would be a blunt response to the lack of federal progress on Vulnerability Disclosure Programs. Programs to allow outside experts to report cybersecurity problems are commonplace in the private sector, but less than 10 civilian agencies have VDPs in place, according to the Cybersecurity and Infrastructure Security Agency.

A draft BOD has reportedly been in the works for months. It outlines key principles that every agency’s VDP should have, including legal protections for researchers who report bugs, expectations for how agencies will move to fix those bugs, and the scope of agency assets that a program should cover. One proposal on the table is for CISA to set up a central portal that would allow other agencies to receive vulnerability reports from researchers.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.