CISA Whitepaper Charts Path to Establishing and Maturing CVE Program Quality
Washington, DC – Today, the Cybersecurity and Infrastructure Security Agency (CISA) released a whitepaper, CVE Program: Establishing a Quality Era Framework, that outlines how we plan to implement our strategy and execute a program-wide maturation effort to the Common Vulnerabilities and Exposures (CVE) Program—the global standard for vulnerability identification—transitioning the program from its Growth Era, to a new Quality Era.
With new CVE Numbering Authorities (CNAs) and Roots joining from around the world, along with artificial intelligence (AI)-enabled technologies adding new pressures to the software lifecycle, CISA recognizes that the program has reached an inflection point and must continue evolving to meet the cybersecurity community’s needs. That’s why last year, we published our strategy outlining the six lines of effort for transitioning the CVE Program to the Quality Era.
Aligned with our strategy, this whitepaper provides key details and actions about the framework CISA is implementing to advance quality across four key dimensions:
- Program governance that is transparent and effective,
- Ecosystem participation that includes broad, active and global community representation,
- Data infrastructure that is robust and supports core CVE operational functions,and
- CVE record content that cyber defenders and users can rely on with confidence.
“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail. Our close collaboration with global industry and government partners is a primary reason the CVE Program remains a trusted, useful source,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort. We encourage the CVE community to review this paper and provide feedback.”
The CVE program is a common good, underpinning the global vulnerability ecosystem. CISA invites the cybersecurity community to share insights and actively participate as we advance the CVE program together.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original