Summary: The extension of MITRE’s contract to run the Common Vulnerabilities and Exposures (CVE) Program by CISA for 11 months has alleviated concerns over the future of this vital cybersecurity component. The decision followed widespread alarm in the cybersecurity community regarding the imminent expiration of the contract. The long-term future of the CVE program remains uncertain as discussions about potential restructuring continue amidst budget constraints.
Affected: MITRE Corporation, U.S. Cybersecurity and Infrastructure Security Agency (CISA), cybersecurity community
Keypoints :
- The CVE Program is critical for vulnerability management and its potential disruption raised significant concerns.
- CISA executed an 11-month contract extension for MITRE to ensure continuous operation of the CVE Program.
- Former CISA Director Jen Easterly highlighted the serious implications of the contract’s expiration for business risk and national security.
Source: https://thecyberexpress.com/mitre-cve-contract-extended-before-expiration/