Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Pentagon Announces Vulnerability Disclosure Policy

The U.S. Department of Defense (DoD) announced on Monday that it has created a vulnerability disclosure policy that aims to provide guidance to researchers on how to disclose security holes found in the organization’s public-facing websites.

The U.S. Department of Defense (DoD) announced on Monday that it has created a vulnerability disclosure policy that aims to provide guidance to researchers on how to disclose security holes found in the organization’s public-facing websites.

The new vulnerability disclosure policy does not include any rewards. Instead, it provides a legal avenue for reporting flaws and the Pentagon hopes it will encourage the cybersecurity community to help it improve its defenses.

Hackers who find vulnerabilities in any public website owned, operated or controlled by the DoD, particularly defense.gov and .mil domains, can submit a report via HackerOne. The organization has promised to acknowledge reports within three business days and publicly recognize those who submit valid issues.

“The Vulnerability Disclosure Policy is a ‘see something, say something’ policy for the digital domain,” said Secretary of Defense Ash Carter. “We want to encourage computer security researchers to help us improve our defenses. This policy gives them a legal pathway to bolster the department’s cybersecurity and ultimately the nation’s security.”

Registration open for Hack the Army

Following the success of the “Hack the Pentagon” initiative, the DoD decided to award a combined $7 million contract to HackerOne and Synack to help its components launch similar bug bounty programs. The first initiative has been launched by the U.S. Army via the HackerOne platform.

The Hack the Army program was announced earlier this month and the registration period started on Monday. The roughly 500 white hat hackers expected to take part in the challenge can earn thousands of dollars in bounties, the DoD said.

Registration is open until November 28 and the program will run between November 30 and December 21. The DoD pointed out that members of the public need to meet certain conditions to participate, including eligibility to work within the U.S. and not residing in a country under trade sanctions.

Advertisement. Scroll to continue reading.

Over 1,400 hackers signed up for the Hack the Pentagon program that took place this spring. More than 250 of them submitted at least one vulnerability report and 138 submissions were eligible for a bounty. The cost of the pilot was $150,000, half of which represented the bounty rewards.

Related: Identity Management Firm Okta Launches Bug Bounty Program

Related: Facebook Paid Out $5 Million in Bug Bounties Since 2011

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

UK cybersecurity agency NCSC announced Richard Horne as its new CEO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem