DHS Mandates Federal Agencies to Run Vulnerability Disclosure Policy

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2019/11/dhs_mandates_fe.html

The DHS is requiring all federal agencies to develop a vulnerability policy. The goal is that people who discover in government systems have a mechanism for reporting them to someone who might actually do something about it.

The devil is in the details, of course, but this is a welcome development.

The DHS is seeking public feedback.