NIST征求AI时代国家漏洞数据库现代化意见
SOURCE / Federal Register · Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence
原文
Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence
完整原文
The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.
归纳
美国国家标准化技术研究院(NIST)负责运营国家漏洞数据库(NVD),该数据库为美国政府提供基于标准的漏洞管理数据。NIST现征求利益相关方意见,以了解在人工智能及机器可读安全数据日益塑造网络安全环境的背景下,推进NVD现代化的机遇、挑战与优先事项,目标是提升NVD的可扩展性、自动化水平、互操作性、透明度与实用性。
点评
NVD现代化将重塑全球漏洞数据的采集、共享与自动化标准,中国企业在出海和供应链合规中需关注其与美国出口管制及网络安全监管规则的衔接。
法律视角点评
AI 生成 · 人工审核核心关切
NVD现代化将重塑全球漏洞数据的采集、共享与自动化标准,中国企业在出海和供应链合规中需关注其与美国出口管制及网络安全监管规则的衔接。
实务启示
中国法律人应跟踪NVD征集的技术路线与数据格式要求,协助客户提前评估产品漏洞披露、跨境安全数据流转及合同中的互操作性义务。