Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA, International Partners Issue Guidance on Vulnerability Disclosure Programs

by Miles Jamison
July 16, 2026
in Cybersecurity, DHS, News
Chris Butera. The CISA executive commented on the guidance for establishing coordinated vulnerability disclosure programs.

Chris Butera, CISA's acting executive assistant director for cybersecurity, commented on the guidance for establishing coordinated vulnerability disclosure programs.

  • CISA has teamed up with four global partners to release new vulnerability disclosure guidance
  • The guide will help software makers build formal channels for researchers to report vulnerabilities
  • The guidance requires public policies that spell out how to submit, test and track vulnerability reports

The Cybersecurity and Infrastructure Security Agency and four international cybersecurity partners have released guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure, or CVD, programs that support collaboration with security researchers.

Table of Contents

    • You might also like
    • FEMA Appoints Steven McAndrews as CIO
    • Raytheon Lands $23B Navy Tomahawk Missile Contract
    • DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools
  • What Does the New Guidance Cover?
  • Why Did CISA Issue the Guidance?

You might also like

FEMA Appoints Steven McAndrews as CIO

Raytheon Lands $23B Navy Tomahawk Missile Contract

DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools

CISA, International Partners Issue Guidance on Vulnerability Disclosure Programs

Learn how DHS is advancing AI, cyber defense and operational capabilities to strengthen homeland security at the 2026 Homeland Security Summit on Nov. 12. Register now.

What Does the New Guidance Cover?

CISA said Thursday it collaborated with the National Security Agency, the Japan Computer Emergency Response Team Coordination Center, the Netherlands’ National Cyber Security Centre and the U.K.’s National Cyber Security Centre to develop the guidance, titled Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers.

The document provides a structured and transparent framework for working with security researchers who identify vulnerabilities in software, hardware and networks. The agency said organizations can use CVD programs to assess potential risks, strengthen vulnerability management processes and enhance decision-making to strengthen product security for customers.

The guidance builds on CISA’s broader efforts to strengthen vulnerability management, including its Known Exploited Vulnerabilities reporting initiative, which expanded the mechanisms available to researchers and organizations to report cyber threats.

Why Did CISA Issue the Guidance?

Chris Butera, acting executive assistant director for cybersecurity at CISA, said coordinated vulnerability disclosure is foundational to building a secure software ecosystem and that the practices outlined support the agency’s Secure by Design initiative.

“CISA encourages suppliers to establish a coordinated vulnerability disclosure program and build constructive, collaborative relationships with security researchers to enhance product security,” said Butera.

The guidance states that security researchers should have a defined, safe channel through which to disclose vulnerabilities. It provides practices for establishing a disclosure program that signals a commitment to product trustworthiness. It states that a publicly posted policy is necessary to detail how reports are submitted, what testing activities are permitted and what can be expected during the review process, including ongoing communication with researchers as the assessment moves forward.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Air Force Fires AIM-120 From YFQ-44A in Collaborative Combat Aircraft Program Milestone

Next Post

DIU Seeks Commercial Technologies to Beam Power Across Space and to Earth

Recommended For You

CBP to Examine Potential Use of Small UAS in Border Patrol Missions

by Scott Nicholas
September 15, 2017
CBP to Examine Potential Use of Small UAS in Border Patrol Missions

The Customs and Border Protection agency has announced plans to evaluate the use of small unmanned aircraft systems in three border patrol sectors as part of a program to...

Read moreDetails

Steven Basham Named Director of Legislative Liaison at Office of the USAF Secretary

by Scott Nicholas
June 24, 2016
Steven Basham Named Director of Legislative Liaison at Office of the USAF Secretary

Steven Basham Steven Basham, deputy director for requirements of the Joint Staff at the Pentagon, has been appointed as director of legislative liaison at the office of the secretary...

Read moreDetails

GSA Advances OASIS+ Contract Program With New Website, Draft Ordering Guide

by Jane Edwards
May 3, 2024
GSA Advances OASIS+ Contract Program With New Website, Draft Ordering Guide

The General Services Administration’s Office of Professional Services and Human Capital Categories, also known as PSHC, has unveiled the first phase of its new website and draft ordering...

Read moreDetails

Navy Unveils Mobile App to Provide Credentialing, Career Development Info

by Jane Edwards
February 3, 2016
Navy Unveils Mobile App to Provide Credentialing, Career Development Info

The U.S. Naval Education and Training Command has launched a new mobile application designed to provide uniformed personnel information on career development, credentialing and civilian career opportunities, the...

Read moreDetails

Katherine Arrington, Wash100 Award Recipient, CISO for DoD OUSDA, to Speak During Potomac Officers Club’s CMMC Forum 2020 on April 2nd

by William McCormick
July 27, 2020
Katherine Arrington, Wash100 Award Recipient, CISO for DoD OUSDA, to Speak During Potomac Officers Club’s CMMC Forum 2020 on April 2nd

Katherine "Katie" Arrington, chief information security officer (CISO) for the Office of the Under Secretary of Defense for Acquisition (OUSDA) of U.S. Department of Defense (DoD),  will serve...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!