稻草人新闻RSS 聚合阅读

← 返回 🛡️ 网络安全

CISA Whitepaper Charts Path to Establishing and Maturing CVE Program Quality

CISA CISA 2 天前 www.cisa.gov

Official websites use .gov

A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS

A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

America Share: Opens in a new window Opens in a new window Opens in a new window Press Release

CISA Whitepaper Charts Path to Establishing and Maturing CVE Program Quality

New Framework Defines Quality, Explains Strategy Alignment, Establishes Roadmap, and Provides Measurements to Success Released Related topics: Cybersecurity Best Practices , Organizations and Cyber Safety , Cyber Threats and Response

Washington, DC – Today, the Cybersecurity and Infrastructure Security Agency (CISA) released a whitepaper, CVE Program: Establishing a Quality Era Framework, that outlines how we plan to implement our strategy and execute a program-wide maturation effort to the Common Vulnerabilities and Exposures (CVE) Program—the global standard for vulnerability identification—transitioning the program from its Growth Era, to a new Quality Era.

With new CVE Numbering Authorities (CNAs) and Roots joining from around the world, along with artificial intelligence (AI)-enabled technologies adding new pressures to the software lifecycle, CISA recognizes that the program has reached an inflection point and must continue evolving to meet the cybersecurity community’s needs. That’s why last year, we published our strategy outlining the six lines of effort for transitioning the CVE Program to the Quality Era.

Aligned with our strategy, this whitepaper provides key details and actions about the framework CISA is implementing to advance quality across four key dimensions:

“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail. Our close collaboration with global industry and government partners is a primary reason the CVE Program remains a trusted, useful source,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort. We encourage the CVE community to review this paper and provide feedback.”

The CVE program is a common good, underpinning the global vulnerability ecosystem. CISA invites the cybersecurity community to share insights and actively participate as we advance the CVE program together.

For more information, visit the CVE Program webpage.

As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.

Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.

在原文站打开 ↗

Cloudflare Workers 每 3 分钟抓一批,9 批轮完最快约 27 分钟 · 点右上 ↻ 立刻全量抓一次