← All FR Documents
Notice

Agency Information Collection Activities: Vulnerability Reporting Submission Form

In Plain English

What is this Federal Register notice?

This is a notice published in the Federal Register by Homeland Security Department. Notices communicate information, guidance, or policy interpretations but may not create new binding obligations.

Is this rule final?

This document is classified as a notice. It may or may not create enforceable regulatory obligations depending on its specific content.

Who does this apply to?

Consult the full text of this document for specific applicability provisions. The affected parties depend on the regulatory scope defined within.

When does it take effect?

No specific effective date is indicated. Check the full text for date provisions.

Why it matters: This notice communicates agency policy or guidance regarding applicable regulations.

Document Details

Document Number2024-25130
TypeNotice
PublishedOct 30, 2024
Effective Date-
RIN-
Docket IDDocket No. CISA-2024-0027
Text FetchedYes

Agencies & CFR References

Agency Hierarchy:
CFR References:
None

Linked CFR Parts

PartNameAgency
No linked CFR parts

Paired Documents

TypeProposedFinalMethodConf
No paired documents

External Links

⏳ Requirements Extraction Pending

This document's regulatory requirements haven't been extracted yet. Extraction happens automatically during background processing (typically within a few hours of document ingestion).

Federal Register documents are immutable—once extracted, requirements are stored permanently and never need re-processing.

Full Document Text (695 words · ~4 min read)

Text Preserved
<NOTICE> DEPARTMENT OF HOMELAND SECURITY <DEPDOC>[Docket No. CISA-2024-0027]</DEPDOC> <SUBJECT>Agency Information Collection Activities: Vulnerability Reporting Submission Form</SUBJECT> <HD SOURCE="HED">AGENCY:</HD> Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS). <HD SOURCE="HED">ACTION:</HD> 60-Day notice and request for comments; new information collection request and OMB 1670-NEW. <SUM> <HD SOURCE="HED">SUMMARY:</HD> The Vulnerability Management (VM) subdivision within Cybersecurity and Infrastructure Security Agency (CISA) submits the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance in accordance with the Paperwork Reduction Act of 1995. </SUM> <DATES> <HD SOURCE="HED">DATES:</HD> Comments are encouraged and will be accepted until December 30, 2024. </DATES> <HD SOURCE="HED">ADDRESSES:</HD> You may submit comments, identified by docket number Docket # CISA-2024-0027, by following the instructions below for submitting comment via the Federal eRulemaking Portal at <E T="03">http://www.regulations.gov.</E> <E T="03">Instructions:</E> All comments received must include the agency name and docket number Docket # CISA-2024-0027. All comments received will be posted without change to <E T="03">http://www.regulations.gov,</E> including any personal information provided. <E T="03">Docket:</E> For access to the docket to read background documents or comments received, go to <E T="03">http://www.regulations.gov.</E> <FURINF> <HD SOURCE="HED">FOR FURTHER INFORMATION CONTACT:</HD> Kevin Donovan, 202-505-6441, <E T="03">kevin.donovan@mail.cisa.dhs.gov.</E> </FURINF> <SUPLINF> <HD SOURCE="HED">SUPPLEMENTARY INFORMATION:</HD> The Cybersecurity and Infrastructure Security Agency (CISA) operates Coordinated Vulnerability Disclosure (CVD) in partnership with industry stakeholders and community researchers alike. Through this collaboration, CISA provides technical assistance and guidance on detecting and handling security Vulnerability Disclosures, compiles, and analyzes incident information that may threaten information security. 6 U.S.C. 659(c)(1), see also 6 U.S.C. 659(c)(6) (providing for information sharing capabilities as the federal civilian interface for sharing of cybersecurity information and providing technical assistance and risk management support for both Federal Government and non-Federal Government entities). CISA is also authorized to carry out these CVD functions by 6 U.S.C. 659(n) on Coordinated Vulnerability Disclosure, which authorizes CISA to, in coordination with industry and other stakeholders, may develop and adhere to DHS policies and procedures for coordinating vulnerability disclosures. CISA is responsible for performing Coordinated Vulnerability Disclosure, which may originate outside the United States Government (USG) network/community and affect users within the USG and/or broader community, or originate within the USG community and affect users both within and outside of it. Often, therefore, the effective handling of security incidents relies on information sharing among individual users, industry, and the USG, which may be facilitated by and through CISA. A dedicated form on the CISA website will allow for reporting of vulnerabilities that the reporting entity believe to be CISA Coordinated Vulnerability Disclosure (CVD) eligible. Upon submission, CISA will evaluate the information provided, and then will triage through the CVD process, if all CISA scoped CVD requirements are met. For the developmental digital copy of this information collection for review, please contact the POC listed above in this notice request. The Office of Management and Budget is particularly interested in comments which: 1. Evaluate whether the proposed collection of information is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; 2. Evaluate the accuracy of the agency's estimate of the burden of the proposed collection of information, including the validity of the methodology and assumptions used; 3. Enhance the quality, utility, and clarity of the information to be collected; and 4. Minimize the burden of the collection of information on those who are to respond, including through the use of appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology, <E T="03">e.g.,</E> permitting electronic submissions of responses. <HD SOURCE="HD1">Analysis</HD> <E T="03">Agency:</E> Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS). <E T="03">Title:</E> Vulnerability Disclosure Submission Form. <E T="03">OMB Number:</E> 1670-NEW. <E T="03">Frequency:</E> Per report on a voluntary basis. <E T="03">Affected Public:</E> State, Local, Territorial, and Tribal, International, Private sector partners. <E T="03">Number of Respondents:</E> 2,725. <E T="03">Estimated Time per Respondent:</E> 0.167 Hours. <E T="03">Total Burden Hours:</E> 454 Hours. <E T="03">Annualized Respondent Cost:</E> $39,536. <E T="03">Total Annualized Respondent Out-of-Pocket Cost:</E> $0. <E T="03">Total Annualized Government Cost:</E> $63,447. <SIG> <NAME>Robert J. Costello,</NAME> Chief Information Officer, Department of Homeland Security, Cybersecurity and Infrastructure Security Agency. </SIG> </SUPLINF> <FRDOC>[FR Doc. 2024-25130 Filed 10-29-24; 8:45 am]</FRDOC> </NOTICE>
This text is preserved for citation and comparison. View the official version for the authoritative text.