BOD 20-01, Develop and Publish a Vulnerability Disclosure Policy
In effectCISA · Binding Operational Directive · September 2, 2020
Summary
Requires agencies to publish a policy inviting the public to report security flaws, set up procedures to handle reports, widen the policy's scope over time until it covers all internet-facing systems, and report metrics to CISA.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Binding Operational Directive
- Number
- BOD 20-01
- Issued
- September 2, 2020
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.