Bottom line: NIST's modernization efforts aim to improve vulnerability management through AI-driven discovery and assessment.
What's happening: NIST is soliciting public input on modernizing the National Vulnerability Database (NVD), which contains information on over 170,000 publicly disclosed vulnerabilities, including those from the National Security Agency (NSA) and the Department of Energy (DOE). The database is maintained by the National Cybersecurity Alliance (NCA) in collaboration with the National Institute of Standards and Technology (NIST). The NVD is a critical component of the Cybersecurity Framework, and its modernization is expected to significantly enhance vulnerability discovery, risk assessment, and remediation. The modernization effort is focused on leveraging AI and machine learning algorithms to improve the accuracy and speed of vulnerability discovery.
What to do: Security leaders should review NIST's public input solicitation and provide feedback on the proposed modernization of the NVD by June 15, 2023.