Today, the Cybersecurity and Infrastructure Security Agency (CISA) released its Vulnerability Disclosure Policy (VDP) Platform 2023 Annual Report, highlighting the service’s remarkable success in 2023, its second full year of operation. Throughout 2023, CISA focused on advocating for the increased agency adoption of the VDP Platform, supporting federal civilian executive branch (FCEB) agencies in identifying vulnerabilities in their systems, and engaging the public security researcher community.

Public security researchers play a vital role in securing our federal government’s networks. As part of CISA’s persistent and ongoing collaboration with the public security researcher community, CISA issued Binding Operational Directive (BOD) 20-01 in 2020, which requires every FCEB agency to establish a VDP. These VDPs follow industry and community best practices, including giving authorization to participating public security researchers and committing to not pursue legal action for good-faith research.Â

CISA’s VDP Platform complements BOD 20-01 by giving FCEB agencies an easy way to establish a VDP and to engage with public security researchers. CISA appreciates the contributions by thousands of public security researchers to date and looks forward to continuing to further broaden this collaboration in the future.

To learn more about the VDP Platform, please visit the Vulnerability Disclosure Policy (VDP) Platform webpage and view the VDP 101 video on CISA’s YouTube channel.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Krebs, Luber added to Cyber Safety Review Board

May 7, 2024 0 Comments 0 tags

The country’s first Cybersecurity and Infrastructure Security Agency director and the current head of the National Security Agency’s Cybersecurity Directorate are among four new additions to the Cyber Safety Review

Rhadamanthys Malware Deployed By TA547 Against German Targets

April 10, 2024 0 Comments 0 tags

Proofpoint said this is the first time the threat actor has been seen using LLM-generated PowerShell scripts

Advance Fee Fraud Targets Colleges With Free Piano Offers

May 29, 2024 0 Comments 0 tags

Proofpoint discovered over 125,000 emails linked to this scam cluster in the past year