WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 CISA and OMB Release Guidance on Vulnerability Management for Federal Government Agencies
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA and OMB Release Guidance on Vulnerability Management for Federal Government Agencies

Author: Charles Egli

Created: Thursday, September 3, 2020 - 18:05

Categories: Cybersecurity, Federal & State Resources

Yesterday the U.S. Department of Homeland Security Cybersecurity Agency (CISA) and the Office of Management and Budget released three documents providing guidance for how federal government agencies should manage vulnerabilities. The CISA guidance consists of a binding operational directive (BOD) that requires each federal agency to publish a vulnerability disclosure program (VDP) as well as implementation guidance. A VDP tells those who find flaws in an agency’s digital infrastructure where to send a report, what types of testing are authorized for which systems, and what communication to expect in response. CISA notes that publication of agency VDPs will make it easier for users to report vulnerabilities they find in the federal government’s internet-accessible systems. OMB, meanwhile, released the final vulnerability disclosure policy, detailing the overarching approach agencies should take to address new and long-standing cyber vulnerabilities. OMB said a VDP should address five areas, including a clear reporting mechanism, timely feedback and ensuring system owners know about problems found within 48 hours. CISA build on that part of the policy in the BOD and implementation guidance. Read more about the new guidance in a blog by CISA Assistant Director for Cybersecurity Brian Ware and an article from the Federal News Network.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar