Department of Homeland Security
AGENCY:
Cybersecurity and Infrastructure Security Agency, DHS.
ACTION:
Notice of availability; request for comments.
SUMMARY:
Through this notice, CISA is making available a draft binding operational directive that will apply to all Federal, executive branch departments and agencies relating to vulnerability disclosure policies. The draft binding operational directive proposes requiring agencies to develop and publish a vulnerability disclosure policy (VDP) and maintain supporting handling procedures. This notice also requests comment on the draft binding operational directive.
DATES:
Comments are due by December 27, 2019.
ADDRESSES:
You may send comments by any of the following methods:
- Agency Website: For instructions on how to provide comments, please follow the instructions provided at https://cyber.dhs.gov/bod/20-01/.
- Email:BOD.Feedback@cisa.dhs.gov. Include “Draft Binding Operational Directive 20-01” in the subject line of the email.
Instructions: The full text of the draft Binding Operational Directive 20-01 is available at https://cyber.dhs.gov./bod/20-01/. Do not submit comments that include trade secrets, confidential commercial or financial information, Chemical-terrorism Vulnerability Information (CVI), Protected Critical Infrastructure Information (PCII), or Sensitive Security Information (SSI). All written comments received will be posted without alteration at https://github.com/, including any personal information. Contact information submitted through email will not be posted to https://github.com/, except for any name and affiliation included in the comment.