-
-
Notifications
You must be signed in to change notification settings - Fork 66
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
No more mention of VDR in latest version of NIST SP 800-161 #54
Comments
@jbmaillet, feel free to open a pull request with the needed modifications, if you like 👍 |
I believe VDR has been rebranded by NIST as VAR (vulnerability advisory report) and this is indicated on our website. But VDR remains the focus because that's the term people are accustomed to using. https://csrc.nist.gov/glossary/term/vulnerability_advisory_report There's also Vulnerability Report, also mentioned in 161r1. |
@stevespringett thanks for the clarification. And so for the completeness of references: In the original NIST SP 800-161r1 from 2022, VDR where defined in section RA-5 VULNERABILITY MONITORING AND SCANNING, page 131.
As of 2024 in NIST SP 800-161r1-upd1 aka 161 revision 1 update 1:
A shorter definition is also given in Appendix H. Glossary page 298, with the definition of vulnerability advisory report and by contrast of vulnerability report (not advisory) for short. Full quotes:
(I think I understand the intention. As for me I would not say that this was needed, rather that it is another layer of icing on the cake of the VDR/VEX/and now VAR mess.) |
Re-reading @stevespringett article on the OWASP website (https://owasp.org/blog/2023/02/07/vdr-vex-comparison), and searching for the authoritative reference regarding VDR, I noticed that the NIST SP 800-161, originally from 2015, have been superseded:
https://csrc.nist.gov/pubs/sp/800/161/r1/final
The new revision can be found here, published in May 2022, so after @stevespringett article, but including updates as of 11-01-2024 (sic):
https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
...and in this document, all reference to VDR disappeared. The revision history at the end does not specifically mention this change. I have no idea of the motivations behind this (unfortunate IMHO) removal. I must still have the original SP in my archive, I'll try to dig deeper in the section modified. On a higher level the update of this SP as a whole seem to be coming from the EO 14028.
Whatever the reason, as of today, at least this mention of this NIST SP is out of date in the CDX project:
https://github.com/CycloneDX/bom-examples/blob/master/VDR/README.md#distinction-between-vulnerability-disclosure-report-vdr-and-vulnerability-exploitability-exchange-vex
Note that I do not consider that this makes the VDR concept obsolete. Just that the NIST can't be referred to, except for historical purposes.
The text was updated successfully, but these errors were encountered: