Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Emailed comments from the Department of Education, Office of Inspector General #131

Closed
h-m-f-t opened this issue Jan 11, 2020 · 0 comments · Fixed by #152
Closed

Emailed comments from the Department of Education, Office of Inspector General #131

h-m-f-t opened this issue Jan 11, 2020 · 0 comments · Fixed by #152
Labels
20-01 VDP directive

Comments

@h-m-f-t
Copy link
Member

h-m-f-t commented Jan 11, 2020

Thank you for the chance to provide comments on DHS’ draft BOD 20-01 that would require agencies to develop and implement an IT systems vulnerability disclosure policy. We generally support creating a mechanism where individuals can submit vulnerability reports. However, we are concerned about the requirement for such policies to contain commitments to not recommend or pursue legal action for such activities, and the burden such policies would impose on individual departments and agencies to track, respond, and resolve such reports. Specifically, as a law enforcement agency, we believe including a provision in any policy that makes a commitment regarding not pursuing legal action is ill advised because it will be impracticable to determine in many cases when external parties or researchers are proceeding in good faith (and are thus not engaging in criminal conduct like a violation of 18 USC Section 1030) when interfacing with agency IT systems and/or reporting vulnerabilities. In addition, the resources required to implement such a mechanism and policy for most agencies and Departments, particularly those with many outward facing IT systems, will be significant. DHS may want to consider tasking creation and implementation of a policy to an entity like US CERT so that the function is centralized and consistent across Government, rather than creating an unfunded mandate on individual agencies.

Antigone Potamianos
Counsel to the IG
Education OIG

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
20-01 VDP directive
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant