Search

CISA Creates Vulnerability Disclosure Platform For Agencies

CISA Creates Vulnerability Disclosure Platform For Agencies
Eric Goldstein, executive assistant director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency. Photo: DHS

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) last week introduced a new platform that allows federal civilian agencies to enable security researchers to legally probe select information systems and websites and report on vulnerabilities they discover.

The platform follows the release in September 2020 by CISA of a Binding Operational Directive to the federal civilian executive branch requiring most agencies to create a vulnerability disclosure policy (VDP), which establishes mechanisms and methods for people that “find flaws in an agency’s digital infrastructure” where to report and the types of testing allowed for which systems.

The VDP Platform essentially provides a channel for security researchers and others to examine website and public-facing information systems for vulnerabilities, alerting agencies to potential weaknesses in their systems for fixing.

The new “VDP Platform provides a single, centrally managed website that agencies can leverage as the primary point of entry for intaking, triaging, and routing vulnerabilities disclosed by researchers,” Eric Goldstein, CISA’s executive assistant director for cybersecurity, wrote July 29 on the agency’s blog. “It enables researchers and members of the general public to find vulnerabilities in agency websites and submit reports for analysis.”

So far, 11 departments and agencies are participating in the VDP Platform, including DHS. The agencies list their websites that are “in-scope” for security researchers to search for, and report on, vulnerabilities.

The VDP Platform was created by Bugcrowd Inc. and EnDyna for CISA.



Contract Updates

BAE Systems Space & Mission Systems Inc. (Boulder, Colorado) – $48,000,000

BAE Systems Space & Mission Systems Inc., Boulder, Colorado, was awarded a $48,000,000 firm-fixed-price contract for the study, design, development, enhancement, testing, and procurement of advanced communication-electronics technologies. Bids were solicited via the internet with one received. Work locations and…


Portus Stevedoring LLC (Jacksonville, Florida) – $8,292,583

Portus Stevedoring LLC, Jacksonville, Florida, is awarded a not-to-exceed $8,292,583 firm-fixed-price, indefinite-delivery/indefinite-quantity contract with a five-year ordering period for stevedoring and related terminal services. This contract provides for full range of stevedoring and related terminal services to include the receipt,…


Foster Miller doing business as QinetiQ North America (Waltham, Massachusetts) – $11,310,230

Foster Miller, doing business as QinetiQ North America, Waltham, Massachusetts, is awarded an $11,310,230 firm-fixed-price modification to a previously awarded indefinite-delivery/indefinite-quantity contract (N00174-21-D-0019) to exercise Option Year Four for production, engineering support, and post-production support of the MK 2 Man…


EnergySolutions Services Inc. (Oak Ridge, Tennessee) – $13,336,650

EnergySolutions Services Inc., Oak Ridge, Tennessee, is being awarded a $13,336,650 firm-fixed-price, indefinite-delivery/indefinite-quantity contract action (N42158-25-D-E001) for nuclear services for the processing, recycling and disposal of radiologic materials through disassembly, decontamination, metal melting, compaction, incineration, resin sluicing/dewater, bulk waste assay…