To Attest or Not to Attest: Questions from the Trump Cyber Executive Order
hackerone.com | blog | #cisa | #vdp | #policy | #executive-order | #software-supply-chain | #us-government | #nist-ssdf
Summary
Trump's cyber EO rolls back federal validation of software attestations, but vendors must still self-attest to NIST SSDF and run a vulnerability disclosure program (VDP).
- Published
- Collected
Skip to content