Showing posts with label NVD. Show all posts
Showing posts with label NVD. Show all posts

Wednesday, August 12, 2026

Review - NIST Publishes RFI for Updating NVD for AI

Today, DOC’s National Institute of Standards and Technology (NIST) published a request for information (RFI) on “Modernizing the National Vulnerability Database in the Age of Artificial Intelligence”. NIST is looking for input from the cybersecurity community on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. 

According to the document summary: 

“The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.” 

Public Feedback  

NIST is requesting public feedback on, and answers to, the provided questions. NIST is requesting that those public responses be submitted via the Federal eRulemaking Portal (www.Regulations.gov; docket # NIST-2026-0100). Comments should be submitted by October 13th, 2026. 


For more details about the questions proposed, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-rfi-for-updating-nvd - subscription required. 

Wednesday, October 9, 2024

Review - HR 9720 Introduced – NVD AI Update

Last month Rep Ross (D,NC) introduced HR 9720, the AI Incident Reporting and Security Enhancement Act. The bill would require the National Institute of Standards and Technology (NIST) to update the National Vulnerability Database (NVD) definitions and process to encourage voluntary disclosures of artificial intelligence safety and security incidents. NIST would also be required to track AI vulnerability reporting. No new funding is authorized by this legislation.

Moving Forward

Ross and one of her two cosponsors, Rep Obernolte (R,CA), are both members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. With the emphasis in the language on voluntary participation, I see nothing in the bill that would engender organized opposition to this legislation. I suspect that there will be some level of bipartisan support for HR 9720, whether it will be enough to allow the bill to be considered in the full House under the suspension of the rules process remains to be seen.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9720-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */