Earlier this week CISA announced their upgraded coordinated vulnerability disclosure platform, VINCE-NT. This new platform will replace the VINCE CVD hosted by Carnegie Mellon University’s Software Engineering Institute; which was primarily focused on vulnerabilities in industrial control systems. The old VINCE site reports that “after November 17, 2026, all CISA vulnerability reports must be submitted through VINCE-NT.”
According to CISA’s CVD landing page the new VINCE-NT program is designed to expand the CISA CVD program to include:
- Operational technology (OT) and industrial control systems (ICS),
- Internet of things (IoT) devices,
- Medical devices,
- Open source software,
- Artificial intelligence (AI), and
- IT systems.
The new VINCE-NT data collection form is hosted on a CISA.gov web page. As such it is required to provide a reference to the OMB Control Number for that information collection to show that it has been appropriately reported to, and reviewed by, OMB’s Office of Information and Regulatory Affairs (OIRA) to ensure that it conforms to the requirements of the Paperwork Reduction Act (PRA). This new VINCE-NT data collection page does not provide an OMB Control Number. Back in February, OIRA did approve a new ICR for a “CISA Coordinated Vulnerability Disclosure (CVD) Platform” with an OMB Control Number of 1670-0058.
No comments:
Post a Comment