A report from the US Commerce department’s inspector general blames the National Institute of Standards and Technology (NIST) for the ever-growing backlog of vulnerabilities for inclusion in the National Vulnerability Database (NVD). But cybersecurity practitioners say that the backlog, although very real, has and accelerated of those discoveries. That raises questions about whether NVD processes need to be completely re-envisioned.
Inter-agency squabbles
, CTO at Contrast Security.
He noted the revelation that OIG analysts’ vulnerability severity calculations only matched NIST’s 12% of the time, suggests that the measure, used by IT to prioritizes fixes, “is barely better than guessing.” That should worry people more than the backlog does, he said.
Williams also argued that the manual parts of threat analysis no longer make much sense, pointing out that the “easy parts” of security such as scanning and ticketing are already automated.
“We got very good at producing findings and never got good at dealing with them. The real prevention work — threat modeling and looking hard at architecture — is still done by hand by a small number of senior people,” he pointed out. “We automated the wrong half. Where AI can be truly groundbreaking is helping with the expert work we could never hire enough people for, to prevent vulnerabilities in the first place.”
, technical counselor at Info-Tech Research Group, said the NVD issues identified in the report are less of a concern than the fact that too many enterprises have grown addicted to NVD as their sole source of vulnerability truth.
“I would ask the question: why are we waiting for NIST to tell us something that’s important?” Avakian said. “Organizations that are relying so much on the NVD have deeper maturity problems because NVD should be treated as a support function to a vulnerability management program, not the entirety of it.”
Ishraq Khan, CEO of coding productivity tool vendor Kodezi, added that the changing scale of vulnerability discovery is the bigger issue.
“Cybersecurity infrastructure must scale at the same pace as vulnerability discovery. If discovery becomes exponentially faster through automation and AI, while enrichment and analysis remain heavily manual, the gap will continue widening,” Khan said.
“I suspect many CISOs will read this report less as an audit finding and more as a warning sign. The question is no longer whether vulnerabilities can be found. The question is whether the institutions responsible for organizing and prioritizing them can keep pace.”
SOCIAL SHARE CARD GENERATOR