a NIST blog For over two decades, the NIST National Vulnerability Database (NVD) has served as the U.S. government repository for standards-based vulnerability management data and as a foundational resource for cybersecurity risk analysis, vulnerability management, compliance automation, and software security. New Opportunities for the NVD via Automation Our cybersecurity landscape is changing dramatically and is being reconfigured by artificial intelligence (AI) in unique, exciting, and yes, sometimes challenging ways. This is creating openings to potentially leverage AI systems to discover and exploit vulnerabilities — but AI can also serve as a valuable tool to strengthen cybersecurity and speed up response times. As the volume of reported vulnerabilities surges and emerging technologies reshape the threat picture, it is time for traditional vulnerability management practices centered on periodic patching and manual remediation to be transformed toward continuous, automated, and contextual vulnerability management. With the rapid growth of AI-enabled cyber tools and dramatically accelerated technology delivery cycles, NIST aims to improve the NVD’s scalability, automation, interoperability, transparency, and utility — modernizing it for the future. To guide this transformation, NIST released a Request for Information (RFI) and is seeking feedback, especially from technical experts, industry and government leaders, researchers, cybersecurity professionals, and software vendors. This is an “all hands-on deck” moment for this community. Your voice matters. We want to understand your priorities and challenges and to learn about opportunities you see to improve vulnerability management. We are committed to providing you with the information and tools you need to anticipate and deal with software vulnerabilities. Steps We’ve Already Taken We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information. We hope that V-etalon will eventually provide a foundation for the evaluation of vulnerability information. We will be looking for feedback and
Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management
Read the original article
nist.gov →