U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

SP 800-216 (Draft)

Recommendations for Federal Vulnerability Disclosure Guidelines

Date Published: June 2021
Comments Due: August 9, 2021 (public comment period is CLOSED)
Email Questions to: sp800-216-comments@nist.gov

Author(s)

Kim Schaffer (NIST), Peter Mell (NIST), Hung Trinh (NIST)

Announcement

Not all security vulnerabilities can be found through automated processes or testing. Internal and external reporting of security vulnerabilities in software and information systems owned or utilized by the Federal Government is critical to mitigating risk, establishing a robust security posture, and maintaining transparency and trust with the public. In 2020 alone, more than 18,000 vulnerabilities were publicly listed in the National Vulnerability Database (NVD).

NIST is inviting comments on this Draft NIST Special Publication, which establishes a flexible, unified framework for establishing policies and implementing procedures for reporting, assessing, and managing vulnerability disclosures for systems within the Federal Government. Per the Internet of Things Cybersecurity Improvement Act of 2020, Public Law 116-207, and in alignment with ISO/IEC 29147 and ISO/IEC30111, these guidelines address:

  • The establishment of a federal vulnerability disclosure framework, including the Federal Coordination Board (FCB) and Vulnerability Disclosure Program Offices (VDPOs)
  • The receipt of information about potential security vulnerabilities in information systems owned or controlled by a government agency
  • The dissemination of information about security vulnerability resolutions to government agencies and the public

NIST is leading this government-wide effort in coordination with other agencies, including the Office of Management and Budget (OMB), the Department of Defense (DoD), and the Department of Homeland Security (DHS).

We encourage you to use the comment template for documenting your comments on the draft.

NOTE: A call for patent claims is included on page iii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Abstract

Keywords

Federal Coordination Body; vulnerability communication; Vulnerability Disclosure; Vulnerability Disclosure Policy; Vulnerability Disclosure Program Office; vulnerability processing; vulnerability tracking
Control Families

None selected

Documentation

Publication:
SP 800-216 (Draft) (DOI)
Local Download

Supplemental Material:
Comment template (xls)

Document History:
06/07/21: SP 800-216 (Draft)
05/24/23: SP 800-216 (Final)

Topics

Security and Privacy
threats; vulnerability management

Laws and Regulations
Internet of Things Cybersecurity Improvement Act