[20200908]IN11497_网络安全:关于联邦漏洞披露计划的最新政策和指南 .pdf

上传人:任我行 文档编号:29709 上传时间:2022-06-24 发布时间:2020-09-08 格式:PDF 页数:4 大小:762.12KB
下载 相关 举报
[20200908]IN11497_网络安全:关于联邦漏洞披露计划的最新政策和指南 .pdf_第1页
第1页 / 共4页
[20200908]IN11497_网络安全:关于联邦漏洞披露计划的最新政策和指南 .pdf_第2页
第2页 / 共4页
[20200908]IN11497_网络安全:关于联邦漏洞披露计划的最新政策和指南 .pdf_第3页
第3页 / 共4页
[20200908]IN11497_网络安全:关于联邦漏洞披露计划的最新政策和指南 .pdf_第4页
第4页 / 共4页
亲,该文档总共4页,全部预览完了,如果喜欢就下载吧!
资源描述

1、CRS INSIGHT Prepared for Members and Committees of Congress INSIGHTINSIGHTi i Cybersecurity: Recent Policy and Guidance on Federal Vulnerability Disclosure Programs September 8, 2020 The Trump Administration has released policy and guidance on vulnerability disclosure programs (VDP) for federal agen

2、cies. VDPs help organizations secure their information technology (IT) by allowing the public to discover and report weaknesses in systems in the hope that the organization will mitigate the vulnerabilities. Vulnerabilities can be exploited by malicious actors to compromise systems, which may lead t

3、o data breaches. On September 2, 2020, the Office of Management and Budget (OMB) released Memorandum M-20-32 on Improving Vulnerability Identification, Management, and Remediation and the Cybersecurity and Infrastructure Security Agency (CISA) released Binding Operational Directive 20-01 (BOD) to De

4、velop and Publish a Vulnerability Disclosure Policy. Policies Memorandum M-20-32 establishes the policy of a federal VDP and agency responsibilities. The memorandum states that a VDP includes traditional vulnerability disclosure policies (i.e., an open program where the public can find vulnerabiliti

展开阅读全文
相关资源
猜你喜欢
相关搜索
资源标签

当前位置:首页 > 法规条令 > CRS 美国国会研究处报告