Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Emailed comment from Adam Bernstein, HUD OIG #83

Closed
h-m-f-t opened this issue Dec 5, 2019 · 2 comments · Fixed by #152
Closed

Emailed comment from Adam Bernstein, HUD OIG #83

h-m-f-t opened this issue Dec 5, 2019 · 2 comments · Fixed by #152
Labels
20-01 VDP directive

Comments

@h-m-f-t
Copy link
Member

h-m-f-t commented Dec 5, 2019

US government agencies currently have many systems in operation with known vulnerabilities and weaknesses and limited funds or resources to mitigate the issues. The agencies continue to operate the systems because they accept the security risk in order to not impede the agency mission. If the systems become non-operational during an attack, then the assumption is that appropriations will then be provided to mitigate the issue. These legacy and underfunded systems should never be a part of any vulnerability disclosure program because the discovery of more vulnerabilities without the ability for remediation will only further weaken the country’s IT systems.

@h-m-f-t h-m-f-t added the 20-01 VDP directive label Dec 5, 2019
@ahouseholder
Copy link

The vulnerabilities are already there, and attackers can find them and won't tell you about them. Bringing attention to the underfunding seems like it would be a good thing, no?

@aro-usdot
Copy link

Acknowledging that the vulnerabilities are there, and the underlying problem that many Federal programs are underresourced to address cybersecurity program requirements and vulnerability mitigation, is a VDP the solution to what is essentially a resource availability, allocation and/or prioritization problem?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
20-01 VDP directive
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants