NIST: Vulnerability Disclosure as a Requirement for Every Organization

Earlier this month, the National Institute of Standard and Technology’s (NIST) cybersecurity framework released a revision (1.1, Draft 2) of its Framework for Improving Critical Infrastructure Cybersecurity. The new release now includes vulnerability disclosure processes as part of the Framework Core (on page 43). This revision contains an important addition, the result of an industry effort. Last

By Cybersecurity NewsVulnerability Disclosure
Why More Government Agencies Need Bug Bounty and Vulnerability Disclosure Programs

If you’re reading this article, statistically speaking your organization might be getting hacked. Data breaches of U.S. government networks, once novel, have become pervasive over the past year. Take it from the Office of Personnel Management (OPM) or the IRS – no one is safe anymore. In private sector, the Equifax hack and Intel’s processor vulnerabilities have hit mainstream media by storm. The

By Bug Bounty ManagementCybersecurity NewsVulnerability Disclosure