80_FR_70980 80 FR 70760 - Multistakeholder Process To Promote Collaboration on Vulnerability Research Disclosure

80 FR 70760 - Multistakeholder Process To Promote Collaboration on Vulnerability Research Disclosure

DEPARTMENT OF COMMERCE
National Telecommunications and Information Administration

Federal Register Volume 80, Issue 220 (November 16, 2015)

Page Range70760-70761
FR Document2015-28933

The National Telecommunications and Information Administration (NTIA) will convene a meeting of a multistakeholder process concerning the collaboration between security researchers and software and system developers and owners to address security vulnerability disclosure on December 2, 2015.

Federal Register, Volume 80 Issue 220 (Monday, November 16, 2015)
[Federal Register Volume 80, Number 220 (Monday, November 16, 2015)]
[Notices]
[Pages 70760-70761]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2015-28933]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Telecommunications and Information Administration


Multistakeholder Process To Promote Collaboration on 
Vulnerability Research Disclosure

AGENCY: National Telecommunications and Information Administration, 
U.S. Department of Commerce.

ACTION: Notice of open meeting.

-----------------------------------------------------------------------

SUMMARY: The National Telecommunications and Information Administration 
(NTIA) will convene a meeting of a multistakeholder process concerning 
the collaboration between security researchers and software and system 
developers and owners to address security vulnerability disclosure on 
December 2, 2015.

DATES: The meeting will be held on December 2, 2015 from 10:30 a.m. to 
4:30 p.m., Eastern Time. See Supplementary Information for details.

[[Page 70761]]


ADDRESSES: The meeting will be held at the 20 F Street NW Conference 
Center, 20 F Street NW., Washington, DC 20001.

FOR FURTHER INFORMATION CONTACT: Allan Friedman, National 
Telecommunications and Information Administration, U.S. Department of 
Commerce, 1401 Constitution Avenue NW., Room 4725, Washington, DC 
20230; telephone (202) 482-4281; email; [email protected]. Please 
direct media inquiries to NTIA's Office of Public Affairs, (202) 482-
7002; email [email protected].

SUPPLEMENTARY INFORMATION: 
    Background: On March 19, 2015, the National Telecommunications and 
Information Administration, working with the Department of Commerce's 
Internet Policy Task Force (IPTF), issued a Request for Comment to 
``identify substantive cybersecurity issues that affect the digital 
ecosystem and digital economic growth where broad consensus, 
coordinated action, and the development of best practices could 
substantially improve security for organizations and consumers.'' \1\ 
This Request built on earlier work from the Department, including the 
2011 Green Paper Cybersecurity, Innovation, and the Internet 
Economy,\2\ as well as comments the Department had received on related 
issues.\3\ On July 9, 2015, after reviewing the comments, NTIA 
announced that the first issue to be addressed would be ``collaboration 
on vulnerability research disclosure,'' \4\ and subsequently announced 
that the first meeting of a multistakeholder process on this topic 
would be held on September 29, 2015.\5\
---------------------------------------------------------------------------

    \1\ U.S. Department of Commerce, Internet Policy Task Force, 
Request for Public Comment, Stakeholder Engagement on Cybersecurity 
in the Digital Ecosystem, 80 FR 14360, Docket No. 150312253-5253-01 
(Mar. 19, 2015), available at: http://www.ntia.doc.gov/files/ntia/publications/cybersecurity_rfc_03192015.pdf.
    \2\ U.S. Department of Commerce, Internet Policy Task Force, 
Cybersecurity, Innovation, and the Internet Economy (June 2011) 
(Green Paper), available at: http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf.
    \3\ See Comments Received in Response to Federal Register Notice 
Developing a Framework for Improving Critical Infrastructure 
Cybersecurity, Docket No. 140721609-4609-01, available at: http://csrc.nist.gov/cyberframework/rfi_comments_10_2014.html.
    \4\ NTIA, Enhancing the Digital Economy Through Collaboration on 
Vulnerability Research Disclosure (July 9, 2015), available at: 
http://www.ntia.doc.gov/blog/2015/enhancing-digital-economy-through-collaboration-vulnerability-research-disclosure.
    \5\ NTIA, Cybersecurity Vulnerabilities, http://www.ntia.doc.gov/other-publication/2015/multistakeholder-process-cybersecurity-vulnerabilities.
---------------------------------------------------------------------------

    Matters to Be Considered: The December 2, 2015 meeting is a 
continuation of a series of NTIA-convened multistakeholder discussions 
concerning collaboration on vulnerability disclosure. Stakeholders will 
engage in an open, transparent, consensus-driven process to develop 
voluntary principles guiding the collaboration between vendors and 
researchers about vulnerability information. The December 2, 2015 
meeting will build on stakeholders' previous work. More information 
about stakeholders' work is available at: http://www.ntia.doc.gov/other-publication/2015/multistakeholder-process-cybersecurity-vulnerabilities.
    Time and Date: NTIA will convene a meeting of the multistakeholder 
process to promote collaboration on vulnerability research disclosure 
on December 2, 2015, from 10:30 a.m. to 4:30 p.m., Eastern Time. The 
meeting date and time are subject to change. Please refer to NTIA's Web 
site, http://www.ntia.doc.gov/other-publication/2015/multistakeholder-process-cybersecurity-vulnerabilities, for the most current 
information.
    Place: The meeting will be held at 20 F Street NW Conference 
Center, 20 F Street NW., Washington, DC 20001. The location of the 
meeting is subject to change. Please refer to NTIA's Web site, http://www.ntia.doc.gov/other-publication/2015/multistakeholder-process-cybersecurity-vulnerabilities, for the most current information.
    Other Information: The meeting is open to the public and the press. 
The meeting is physically accessible to people with disabilities. 
Requests for sign language interpretation or other auxiliary aids 
should be directed to John Verdi at (202) 482-8238 or 
[email protected] at least seven (7) business days prior to the 
meeting. The meeting will also be webcast. Requests for real-time 
captioning of the webcast or other auxiliary aids should be directed to 
Allan Friedman at (202) 482-4281 or [email protected] at least 
seven (7) business days prior to the meeting. There will be an 
opportunity for stakeholders viewing the webcast to participate 
remotely in the meeting through a moderated conference bridge, 
including polling functionality. Access details for the meeting are 
subject to change. Please refer to NTIA's Web site, http://www.ntia.doc.gov/other-publication/2015/multistakeholder-process-cybersecurity-vulnerabilities, for the most current information.

    Dated: November 10, 2015.
Kathy D. Smith,
Chief Counsel, National Telecommunications and Information 
Administration.
[FR Doc. 2015-28933 Filed 11-13-15; 8:45 am]
BILLING CODE 3510-60-P



                                              70760                      Federal Register / Vol. 80, No. 220 / Monday, November 16, 2015 / Notices

                                              requested permit amendment has been                     DEPARTMENT OF COMMERCE                                number of research-related mortality is
                                              issued under the authority of the Marine                                                                      also allowed, as well as world-wide
                                              Mammal Protection Act of 1972, as                       National Oceanic and Atmospheric                      import and export of pinniped samples.
                                              amended (16 U.S.C. 1361 et seq.), and                   Administration                                        A minor amendment (Permit No.
                                              the regulations governing the taking and                RIN 0648–XC014                                        17670–01) authorized sampling of
                                              importing of marine mammals (50 CFR                                                                           pinniped carcasses aboard commercial
                                              part 216).                                              Marine Mammals; File No. 17670                        fishing vessels. An additional minor
                                                                                                                                                            amendment (Permit No. 17670–02)
                                                 Permit No. 17952 authorized long-                    AGENCY:  National Marine Fisheries                    authorized nail clipping and fecal loop
                                              term research on California sea lions to                Service (NMFS), National Oceanic and                  sampling during permitted captures.
                                              study their foraging, diving, energetics,               Atmospheric Administration (NOAA),                       Permit No. 17670–03, issued
                                              food habits, and at sea distribution                    Commerce.                                             September 28, 2015, includes
                                              through capture, sampling, and tagging                  ACTION: Notice; issuance of permit                    authorization to increase the number
                                              California sea lions throughout their                   amendment.                                            and frequency of gray and harbor seal
                                              U.S. range (California, Oregon and                                                                            harassment and capture takes annually
                                              Washington). The permit also                            SUMMARY:  Notice is hereby given that a
                                                                                                                                                            during research, add use of unmanned
                                              authorized harassment of California sea                 major amendment to Permit No. 17670–
                                                                                                                                                            aircraft systems to survey seals, increase
                                              lions, harbor seals (Phoca vitulina), and               02 has been issued to NMFS Northeast
                                                                                                                                                            the number of biopsy samples taken
                                              northern elephant seals (Mirounga                       Fisheries Science Center, 166 Water
                                                                                                                                                            (from one to two), increase the number
                                                                                                      Street, Woods Hole, MA 02543
                                              angustirostris) incidental to research                                                                        of gray and harbor seal samples
                                                                                                      (Responsible Party: William Karp,
                                              activities, unintentional mortalities of                                                                      imported/exported annually, and allow
                                                                                                      Ph.D.).
                                              California sea lions, and import and                                                                          euthanasia in the event sick or injured
                                              export of pinniped samples. A minor                     ADDRESSES:   The permit amendment and                 seals are inadvertently captured. The
                                              amendment (Permit No. 17952–01)                         related documents are available for                   permit expires April 30, 2018.
                                              included attachment of cameras to                       review upon written request or by                        In compliance with the National
                                              instrumentation deployed on sea lions                   appointment in the Permits and                        Environmental Policy Act of 1969 (42
                                              and intubation during gas anesthesia.                   Conservation Division, Office of                      U.S.C. 4321 et seq.), a final
                                                                                                      Protected Resources, NMFS, 1315 East-                 determination has been made that the
                                                 Permit No. 17952–02, issued on                       West Highway, Room 13705, Silver                      activity proposed is categorically
                                              September 30, 2015, includes                            Spring, MD 20910; phone (301) 427–                    excluded from the requirement to
                                              authorization to (1) add remote darting                 8401; fax (301) 713–0376.                             prepare an environmental assessment or
                                              as an approved capture method with use                  FOR FURTHER INFORMATION CONTACT:                      environmental impact statement.
                                              of various sedative drugs for adult and                 Amy Sloan or Rosa L. González, (301)
                                              juvenile California sea lions, (2) increase                                                                     Dated: October 29, 2015.
                                                                                                      427–8401.
                                              incidental harassment takes of non-                                                                           Julia Harrison,
                                                                                                      SUPPLEMENTARY INFORMATION: On July
                                              target California sea lions, (3) include                                                                      Chief, Permits and Conservation Division,
                                                                                                      10, 2015, notice was published in the                 Office of Protected Resources, National
                                              incidental harassment takes for the                     Federal Register (80 FR 39749) that a                 Marine Fisheries Service.
                                              Eastern stock of Steller sea lions                      request for an amendment Permit No.                   [FR Doc. 2015–28838 Filed 11–13–15; 8:45 am]
                                              (Eumetopias jubatus), and (4) include                   17670–02 to conduct research on gray
                                                                                                                                                            BILLING CODE 3510–22–P
                                              takes for capture and disentanglement of                (Halichoerus grypus), harbor (Phoca
                                              California sea lions. The authorized                    vitulina), harp (Pagophilus
                                              takes are delineated in the amendment                   groenlandicus), and hooded                            DEPARTMENT OF COMMERCE
                                              application and amended permit and                      (Cystophora cristata) seals had been
                                              are authorized for the duration of the                  submitted by the above-named                          National Telecommunications and
                                              permit. The permit expires June 7, 2018.                applicant. The requested permit                       Information Administration
                                                 In compliance with the National                      amendment has been issued under the
                                                                                                      authority of the Marine Mammal                        Multistakeholder Process To Promote
                                              Environmental Policy Act of 1969 (42
                                                                                                      Protection Act of 1972, as amended (16                Collaboration on Vulnerability
                                              U.S.C. 4321 et seq.), a final
                                                                                                      U.S.C. 1361 et seq.), and the regulations             Research Disclosure
                                              determination has been made that the
                                                                                                      governing the taking and importing of
                                              activity proposed is categorically                                                                            AGENCY:  National Telecommunications
                                                                                                      marine mammals (50 CFR part 216).
                                              excluded from the requirement to                           Permit No. 17670–00 authorized takes               and Information Administration, U.S.
                                              prepare an environmental assessment or                  of gray, harbor, harp, and hooded seals               Department of Commerce.
                                              environmental impact statement.                         in waters within or proximal to the U.S.              ACTION: Notice of open meeting.
                                                Dated: October 29, 2015.                              EEZ from North Carolina northward to
                                                                                                      Maine, during conduct of stock                        SUMMARY:   The National
                                              Julia Harrison,
                                                                                                      assessment research, including                        Telecommunications and Information
                                              Chief, Permits and Conservation Division,                                                                     Administration (NTIA) will convene a
                                              Office of Protected Resources, National                 estimation of distribution and
                                                                                                      abundance, determination of stock                     meeting of a multistakeholder process
                                              Marine Fisheries Service.
                                                                                                      structure, habitat requirements, foraging             concerning the collaboration between
                                              [FR Doc. 2015–28841 Filed 11–13–15; 8:45 am]                                                                  security researchers and software and
                                                                                                      ecology, health assessment and effects
                                              BILLING CODE 3510–22–P                                                                                        system developers and owners to
tkelley on DSK3SPTVN1PROD with NOTICES




                                                                                                      of natural and anthropogenic factors.
                                                                                                      Types of take include harassment                      address security vulnerability disclosure
                                                                                                      during shipboard, skiff, and aircraft                 on December 2, 2015.
                                                                                                      transect and photo-identification                     DATES: The meeting will be held on
                                                                                                      surveys, and scat collection; and,                    December 2, 2015 from 10:30 a.m. to
                                                                                                      capture with tissue sampling and                      4:30 p.m., Eastern Time. See
                                                                                                      instrument or tag attachment. A limited               Supplementary Information for details.


                                         VerDate Sep<11>2014   19:47 Nov 13, 2015   Jkt 238001   PO 00000   Frm 00014   Fmt 4703   Sfmt 4703   E:\FR\FM\16NON1.SGM   16NON1


                                                                         Federal Register / Vol. 80, No. 220 / Monday, November 16, 2015 / Notices                                                 70761

                                              ADDRESSES:   The meeting will be held at                continuation of a series of NTIA-                       Dated: November 10, 2015.
                                              the 20 F Street NW Conference Center,                   convened multistakeholder discussions                 Kathy D. Smith,
                                              20 F Street NW., Washington, DC 20001.                  concerning collaboration on                           Chief Counsel, National Telecommunications
                                              FOR FURTHER INFORMATION CONTACT:                        vulnerability disclosure. Stakeholders                and Information Administration.
                                              Allan Friedman, National                                will engage in an open, transparent,                  [FR Doc. 2015–28933 Filed 11–13–15; 8:45 am]
                                              Telecommunications and Information                      consensus-driven process to develop                   BILLING CODE 3510–60–P
                                              Administration, U.S. Department of                      voluntary principles guiding the
                                              Commerce, 1401 Constitution Avenue                      collaboration between vendors and
                                              NW., Room 4725, Washington, DC                          researchers about vulnerability                       COMMITTEE FOR PURCHASE FROM
                                              20230; telephone (202) 482–4281; email;                 information. The December 2, 2015                     PEOPLE WHO ARE BLIND OR
                                              afriedman@ntia.doc.gov. Please direct                   meeting will build on stakeholders’                   SEVERELY DISABLED
                                              media inquiries to NTIA’s Office of                     previous work. More information about
                                              Public Affairs, (202) 482–7002; email                   stakeholders’ work is available at:                   Procurement List; Proposed Additions
                                              press@ntia.doc.gov.                                     http://www.ntia.doc.gov/other-                        AGENCY:  Committee for Purchase From
                                              SUPPLEMENTARY INFORMATION:                              publication/2015/multistakeholder-                    People Who Are Blind or Severely
                                                 Background: On March 19, 2015, the                   process-cybersecurity-vulnerabilities.                Disabled.
                                              National Telecommunications and
                                                                                                        Time and Date: NTIA will convene a                  ACTION: Proposed additions to the
                                              Information Administration, working
                                              with the Department of Commerce’s                       meeting of the multistakeholder process               Procurement List.
                                              Internet Policy Task Force (IPTF),                      to promote collaboration on
                                                                                                      vulnerability research disclosure on                  SUMMARY:   The Committee is proposing
                                              issued a Request for Comment to                                                                               to add products to the Procurement List
                                              ‘‘identify substantive cybersecurity                    December 2, 2015, from 10:30 a.m. to
                                                                                                                                                            that will be furnished by nonprofit
                                              issues that affect the digital ecosystem                4:30 p.m., Eastern Time. The meeting
                                                                                                                                                            agencies employing persons who are
                                              and digital economic growth where                       date and time are subject to change.                  blind or have other severe disabilities.
                                              broad consensus, coordinated action,                    Please refer to NTIA’s Web site, http://
                                                                                                                                                            DATES: Comments must be received on
                                              and the development of best practices                   www.ntia.doc.gov/other-publication/
                                                                                                                                                            or before: December 16, 2015.
                                              could substantially improve security for                2015/multistakeholder-process-
                                              organizations and consumers.’’ 1 This                   cybersecurity-vulnerabilities, for the                ADDRESSES: Committee for Purchase
                                              Request built on earlier work from the                  most current information.                             From People Who Are Blind or Severely
                                              Department, including the 2011 Green                                                                          Disabled, 1401 S. Clark Street, Suite
                                                                                                        Place: The meeting will be held at 20               715, Arlington, Virginia 22202–4149.
                                              Paper Cybersecurity, Innovation, and
                                                                                                      F Street NW Conference Center, 20 F
                                              the Internet Economy,2 as well as                                                                             FOR FURTHER INFORMATION CONTACT:
                                                                                                      Street NW., Washington, DC 20001. The                 Barry S. Lineback, Telephone: (703)
                                              comments the Department had received
                                                                                                      location of the meeting is subject to                 603–7740, Fax: (703) 603–0655, or email
                                              on related issues.3 On July 9, 2015, after
                                              reviewing the comments, NTIA                            change. Please refer to NTIA’s Web site,              CMTEFedReg@AbilityOne.gov.
                                              announced that the first issue to be                    http://www.ntia.doc.gov/other-
                                                                                                                                                            SUPPLEMENTARY INFORMATION: This
                                              addressed would be ‘‘collaboration on                   publication/2015/multistakeholder-
                                                                                                                                                            notice is published pursuant to 41
                                              vulnerability research disclosure,’’ 4 and              process-cybersecurity-vulnerabilities, for            U.S.C. 8503(a)(2) and 41 CFR 51–2.3. Its
                                              subsequently announced that the first                   the most current information.                         purpose is to provide interested persons
                                              meeting of a multistakeholder process                     Other Information: The meeting is                   an opportunity to submit comments on
                                              on this topic would be held on                          open to the public and the press. The                 the proposed actions.
                                              September 29, 2015.5                                    meeting is physically accessible to
                                                 Matters to Be Considered: The                                                                              Additions
                                                                                                      people with disabilities. Requests for
                                              December 2, 2015 meeting is a                           sign language interpretation or other                    If the Committee approves the
                                                                                                      auxiliary aids should be directed to John             proposed additions, the entities of the
                                                 1 U.S. Department of Commerce, Internet Policy
                                                                                                      Verdi at (202) 482–8238 or jverdi@                    Federal Government identified in this
                                              Task Force, Request for Public Comment,                                                                       notice will be required to procure the
                                              Stakeholder Engagement on Cybersecurity in the          ntia.doc.gov at least seven (7) business
                                              Digital Ecosystem, 80 FR 14360, Docket No.              days prior to the meeting. The meeting                products listed below from nonprofit
                                              150312253–5253–01 (Mar. 19, 2015), available at:        will also be webcast. Requests for real-              agencies employing persons who are
                                              http://www.ntia.doc.gov/files/ntia/publications/
                                                                                                      time captioning of the webcast or other               blind or have other severe disabilities.
                                              cybersecurity_rfc_03192015.pdf.                                                                                  The following products are proposed
                                                 2 U.S. Department of Commerce, Internet Policy       auxiliary aids should be directed to
                                                                                                                                                            for addition to the Procurement List for
                                              Task Force, Cybersecurity, Innovation, and the          Allan Friedman at (202) 482–4281 or
                                              Internet Economy (June 2011) (Green Paper),                                                                   production by the nonprofit agencies
                                              available at: http://www.nist.gov/itl/upload/
                                                                                                      afriedman@ntia.doc.gov at least seven                 listed:
                                              Cybersecurity_Green-Paper_FinalVersion.pdf.             (7) business days prior to the meeting.
                                                 3 See Comments Received in Response to Federal       There will be an opportunity for                      Product Name(s)—NSN(s): Coat, Army
                                              Register Notice Developing a Framework for                                                                        Combat Uniform, Permethrin, Unisex,
                                                                                                      stakeholders viewing the webcast to                       OCP 2015
                                              Improving Critical Infrastructure Cybersecurity,
                                              Docket No. 140721609–4609–01, available at:
                                                                                                      participate remotely in the meeting                     8415–01–623–5052—XS–XXS
                                              http://csrc.nist.gov/cyberframework/rfi_comments_       through a moderated conference bridge,                  8415–01–623–5162—XS–XS
                                              10_2014.html.                                           including polling functionality. Access                 8415–01–623–5165—XS–S
                                                 4 NTIA, Enhancing the Digital Economy Through
                                                                                                      details for the meeting are subject to                  8415–01–623–5166—XS–R
                                              Collaboration on Vulnerability Research Disclosure                                                              8415–01–623–5169—XS–L
tkelley on DSK3SPTVN1PROD with NOTICES




                                              (July 9, 2015), available at: http://                   change. Please refer to NTIA’s Web site,
                                                                                                                                                              8415–01–623–5170—XS–XL
                                              www.ntia.doc.gov/blog/2015/enhancing-digital-           http://www.ntia.doc.gov/other-
                                              economy-through-collaboration-vulnerability-
                                                                                                                                                              8415–01–623–5172—S–XXS
                                                                                                      publication/2015/multistakeholder-                      8415–01–623–5174—S–XS
                                              research-disclosure.
                                                 5 NTIA, Cybersecurity Vulnerabilities, http://
                                                                                                      process-cybersecurity-vulnerabilities, for              8415–01–623–5178—S–S
                                              www.ntia.doc.gov/other-publication/2015/                the most current information.                           8415–01–623–5180—S–R
                                              multistakeholder-process-cybersecurity-                                                                         8415–01–623–5182—S–L
                                              vulnerabilities.                                                                                                8415–01–623–5236—S–XL



                                         VerDate Sep<11>2014   19:47 Nov 13, 2015   Jkt 238001   PO 00000   Frm 00015   Fmt 4703   Sfmt 4703   E:\FR\FM\16NON1.SGM   16NON1



Document Created: 2015-12-14 14:13:12
Document Modified: 2015-12-14 14:13:12
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of open meeting.
DatesThe meeting will be held on December 2, 2015 from 10:30 a.m. to 4:30 p.m., Eastern Time. See Supplementary Information for details.
ContactAllan Friedman, National Telecommunications and Information Administration, U.S. Department of Commerce, 1401 Constitution Avenue NW., Room 4725, Washington, DC 20230; telephone (202) 482-4281; email; [email protected] Please direct media inquiries to NTIA's Office of Public Affairs, (202) 482- 7002; email [email protected]
FR Citation80 FR 70760 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR