<p>A contracting scare that briefly cast uncertainty over a key cyber vulnerability-tracking program is prompting lawmakers to add a measure to the annual defense authorization bill that would establish the program within the Cybersecurity and Infrastructure Security Agency.</p>
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<p>The proposal would formally house the Common Vulnerabilities and Exposures program under CISA, require a joint modernization plan with the National Institute of Standards and Technology and push officials to improve the public vulnerability data used by agencies, companies and security researchers to assess cyber risk, according to the text of the planned amendment viewed by <em>Nextgov/FCW</em>.</p>
<p>CVE provides a standardized methodology for logging publicly known security vulnerabilities. Each flaw is assigned a unique identifier, designed to help researchers, vendors and officials more effectively communicate about the same issue. It first launched in 1999, and is used today by organizations across the private sector and the national intelligence enterprise.</p>
<p>The program faced a contracting debacle last spring when MITRE, the non-profit research giant that funds much of CVE’s functions, warned of an imminent end to federal backing for the project during an efficiency-driven purge of several contracts at CISA. </p>
<p>The matter was <a href=“CISA extends MITRE-backed CVE contract hours before its lapse - Nextgov/FCW”>addressed</a> within hours amid outcry from the cybersecurity community, but it ignited discussions over the long-term stability of a system that much of the cybersecurity community deems critical for day-to-day work. </p>
<p>The proposed NDAA measure is significant because, if passed, it would give CISA a formal, legal role in managing the premier global catalog used across the cybersecurity world to identify, track and prioritize software flaws. </p>
<p>The amendment text reviewed by <em>Nextgov/FCW</em> does not name a sponsoring lawmaker. <em>Nextgov/FCW</em> has also asked CISA for its position on the amendment.</p>
<p>The proposal would also create a 15-member CVE Board to set the program’s policies and priorities, with permanent seats for CISA, NIST and top-level CVE authorities. Rotating members would come from industry, academia, the research community and foreign governments.</p>
<p>It would also put greater weight behind vulnerability enrichment — the process of adding context about a flaw’s severity and how hackers may exploit it — by making it part of CVE’s formal mission and directing the program’s board to set policies for what information CVE records should include.</p>
<p>Earlier this year, EU cybersecurity chief Hans de Vries told an audience at the RSAC Conference in San Francisco that Europe wants to <a href=“EU wants to support bedrock cyber vulnerability program, top official says - Nextgov/FCW”>assist with and help modernize</a> the program.</p>
<p>In the same discussion, a top House Homeland Security Committee staffer <a href=“EU wants to support bedrock cyber vulnerability program, top official says - Nextgov/FCW”>previewed</a> the measure. </p>
<p>“While CISA is certainly authorized to execute this program, it’s not specifically tasked with doing it, which, as an oversight committee, makes it harder for us to hold an agency accountable for executing a task,” said Moira Bergen, who leads cyber policy work for the Democratic side of the panel. </p>
<p>The House Armed Services Committee approved its version of the fiscal 2027 defense bill earlier this month, sending it to the Rules Committee ahead of expected floor consideration. The Rules panel has told members to submit proposed amendments by 5 p.m. Thursday.</p>
<p>The Senate Armed Services Committee also advanced its own version of the bill last week. Once both chambers pass their versions, negotiators from both chambers will have to reconcile differences between the two before a final defense policy package can reach the president.</p>
Article Link: Planned NDAA amendment would codify CISA’s role in cyber vulnerability program - Nextgov/FCW