• National Vulnerability Database can’t keep up with analysis

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » National Vulnerability Database can’t keep up with analysis

    • This topic has 1 reply, 2 voices, and was last updated 1 year ago.
    Author
    Topic
    #2663615

    https://nvd.nist.gov/general/news/nvd-program-transition-announcement

    NVD Program Announcement UPDATED

    NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure.

    There is a growing backlog of vulnerabilities submitted to the NVD and requiring analysis. This is based on a variety of factors, including an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.

    Currently, we are prioritizing analysis of the most significant vulnerabilities. In addition, we are working with our agency partners to bring on more support for analyzing vulnerabilities and have reassigned additional NIST staff to this task as well.

    We are also looking into longer-term solutions to this challenge, including the establishment of a consortium of industry, government, and other stakeholder organizations that can collaborate on research to improve the NVD…

    * This is very bad as many organizations rely on NVD information in their vulnerability management.

    2 users thanked author for this post.
    Viewing 0 reply threads
    Author
    Replies
    Viewing 0 reply threads
    Reply To: National Vulnerability Database can’t keep up with analysis

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: