Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
2,143
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

A federal audit reveals significant issues with the management of the National Vulnerability Database (NVD) by the National Institute of Standards and Technology (NIST), highlighting a backlog of unprocessed vulnerabilities and a lack of a strategic plan, despite previous public assurances of improvement. The U.S. Department of Commerce Office of Inspector General found that NIST set unrealistic deadlines without the capacity to meet them and spent taxpayer money on duplicated vulnerability enrichment work, exacerbating the backlog. NIST's decision to transition to a risk-based model for analyzing vulnerabilities left many records without necessary data for automated management, further contributed to delays, particularly for critical vulnerabilities. The audit also uncovered poor communication and coordination between NIST and the Cybersecurity and Infrastructure Security Agency (CISA), which resulted in redundant efforts and wasted resources. Despite these findings, NIST pushed back against some of the audit's framing but agreed to implement recommendations for improvement, including creating strategic and backlog management plans and enhancing coordination with CISA.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.