Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog
Blog post from Socket
A federal audit reveals significant issues with the management of the National Vulnerability Database (NVD) by the National Institute of Standards and Technology (NIST), highlighting a backlog of unprocessed vulnerabilities and a lack of a strategic plan, despite previous public assurances of improvement. The U.S. Department of Commerce Office of Inspector General found that NIST set unrealistic deadlines without the capacity to meet them and spent taxpayer money on duplicated vulnerability enrichment work, exacerbating the backlog. NIST's decision to transition to a risk-based model for analyzing vulnerabilities left many records without necessary data for automated management, further contributed to delays, particularly for critical vulnerabilities. The audit also uncovered poor communication and coordination between NIST and the Cybersecurity and Infrastructure Security Agency (CISA), which resulted in redundant efforts and wasted resources. Despite these findings, NIST pushed back against some of the audit's framing but agreed to implement recommendations for improvement, including creating strategic and backlog management plans and enhancing coordination with CISA.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.