Common Vulnerabilities and Exposures (CVE) - Managed by

The Common Vulnerabilities and Exposures (CVE) system is primarily managed by:

  • The MITRE Corporation:
    • MITRE is a non-profit organization that operates federally funded research and development centers. They play a central role in maintaining the CVE list.   
  • Cybersecurity and Infrastructure Security Agency (CISA):
    • CISA, which is part of the U.S. Department of Homeland Security, sponsors the CVE program.
  • CVE Numbering Authorities (CNAs):
    • In addition to MITRE, there are various CNAs, which are organizations authorized to assign CVE IDs. These include software vendors, research organizations, and others.   

In summary, while MITRE is the core organization that maintains the CVE list, it's a collaborative effort involving CISA and a network of CNAs.

Comments

Popular posts from this blog

Stop-or-go sampling

Compliance risk

Discovery sampling