• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Crucial Point LLC

Accelerating Technology

  • About Crucial Point
    • About Bob Gourley
    • Announcements
    • Corporate Events
    • Press
    • CTOvision
      • Go Pro!
  • Contact Us
  • Services
    • Technology Due Diligence
    • CTO Advisory Services
    • Compliance and Cybersecurity
    • CTO-as-a-Service
    • CISO-as-a-Service
    • Corporate Events
  • Crucial Point Clients
  • Cybersecurity Best Practices
    • Cybersecurity Best Practices
    • Cybersecurity At Home
    • Health Insurance Portability and Accountability Act (HIPAA) Security Rule Compliance
    • The FFIEC Cybersecurity Assessment Tool Can Be Used To Raise Your Security Posture
    • Companies Who Interact With European Citizens Must Check Architecture For Compliance With New Data Rules

Featured in TheCipherBrief.com Network Take: A Welcome Cyber Disclosure

Home » Announcements » Cybersecurity » Featured in TheCipherBrief.com Network Take: A Welcome Cyber Disclosure

From: Network Take: A Welcome Cyber Disclosure

The Cipher Brief Cyber Advisory Board’s Bob Gourley commented on the Trump administration’s new process for disclosing software vulnerabilities it has detected – the first time a U.S. administration has revealed its internal rules, aka the Vulnerability Equities Process.

This is a significant improvement and clarification of the existing process because it expands the number of stakeholders from government while ensuring there is an expedient method for review.

The vision is clear, there must be a decision-making body that takes multiple considerations into account and can take action.

There is room for additional inputs into the decision-making process. Three that come to mind are input from the commercial sector, input from academia and input from privacy advocates. The commercial sector input will be hard to formalize, but clearly there is room to improve the dialog between the U.S. technology sector and the executive branch regarding vulnerabilities and the current charter focused only on the tactical aspects of vulnerability disclosure.

Strategically, how can our IT industry provide inputs into how the process should work? That is missing from the charter. Academia may play an important role in helping the government understand the lessons of history and the canon of knowledge around cyber conflict that should inform these decisions. The privacy community can provide inputs into smart ways to ensure complex issues over the expectations of privacy our citizens can be protected.

So, a concept for the future: charter a strategic review board made up of industry tech titans, charter an input board made up of seasoned strategic thinkers from academia, and empower an oversight board of leaders from the privacy community.

Crucial Point experts know cybersecurity and the details required to keep your enterprise working well in the face of dynamic threats. Contact us today for more on how we can help via our CTO-as-a-Service offerings.

Filed Under: Cybersecurity, Government Markets, Press

Primary Sidebar

Our Latest

OODA LLC: Put our team of experts on your side

Crucial Point is now part of OODA LLC. OODA helps our clients identify, manage, and respond to global risks and uncertainties while exploring emerging opportunities and developing robust and … [Read More...] about OODA LLC: Put our team of experts on your side