Current Behavior
The current version of Dependency-Track provides support for several open data sources, including the EPSS. It does not currently ingest data from the CISA KEV. Inclusion in the CISA KEV triggers vulnerability remediation timeline requirements for federal agencies as set forth in CISA Binding Operational Directive (BOD) 22-01. Specifically, the BOD 22-01 specifies:
"Remediate each vulnerability according to the timelines set forth in the CISA-managed vulnerability catalog. The catalog will list exploited vulnerabilities that carry significant risk to the federal enterprise with the requirement to remediate within 6 months for vulnerabilities with a Common Vulnerabilities and Exposures (CVE) ID assigned prior to 2021 and within two weeks for all other vulnerabilities. These default timelines may be adjusted in the case of grave risk to the Federal Enterprise."outlined in
Proposed Behavior
I am proposing ingesting the CISA KEV database available at https://www.cisa.gov/known-exploited-vulnerabilities-catalog and using this data to enrich the existing exploitability data such as EPSS also to include the date added to KEV and the remediation due date. Once the data is included, I would request a policy to identify vulnerabilities outside of the KEV remediation timeline.
While the vulnerability due date is currently only applicable to US federal agencies, I could foresee a time when the remediation timeline becomes a requirement for federal contractors.
I had a brief exchange with Steve S. on this in the OWASP Slack channel, and he requested I include a note about building this in a way that isn't specific to the USA. I have spent some time researching international equivalents to the CISA KEV but have not found any. I have found several commercial tools supporting KEV, including:
https://www.tenable.com/sc-dashboards/dhs-cisa-binding-operational-directive-22-01
https://nucleussec.com/cisa-kev/
https://www.paloaltonetworks.com/blog/security-operations/cortex-xpanse-identify-cisa-kev/
https://blog.qualys.com/product-tech/2022/02/22/managing-cisa-known-exploited-vulnerabilities-with-qualys-vmdr
Steve's note from our Slack discussion: "I wonder if other countries have similar things. I'd hate to make it U.S. specific. I'd rather find a non-geographic way to implement this while still being able to use KEV as one of the possible feeds. "
Checklist
Current Behavior
The current version of Dependency-Track provides support for several open data sources, including the EPSS. It does not currently ingest data from the CISA KEV. Inclusion in the CISA KEV triggers vulnerability remediation timeline requirements for federal agencies as set forth in CISA Binding Operational Directive (BOD) 22-01. Specifically, the BOD 22-01 specifies:
"Remediate each vulnerability according to the timelines set forth in the CISA-managed vulnerability catalog. The catalog will list exploited vulnerabilities that carry significant risk to the federal enterprise with the requirement to remediate within 6 months for vulnerabilities with a Common Vulnerabilities and Exposures (CVE) ID assigned prior to 2021 and within two weeks for all other vulnerabilities. These default timelines may be adjusted in the case of grave risk to the Federal Enterprise."outlined in
Proposed Behavior
I am proposing ingesting the CISA KEV database available at https://www.cisa.gov/known-exploited-vulnerabilities-catalog and using this data to enrich the existing exploitability data such as EPSS also to include the date added to KEV and the remediation due date. Once the data is included, I would request a policy to identify vulnerabilities outside of the KEV remediation timeline.
While the vulnerability due date is currently only applicable to US federal agencies, I could foresee a time when the remediation timeline becomes a requirement for federal contractors.
I had a brief exchange with Steve S. on this in the OWASP Slack channel, and he requested I include a note about building this in a way that isn't specific to the USA. I have spent some time researching international equivalents to the CISA KEV but have not found any. I have found several commercial tools supporting KEV, including:
https://www.tenable.com/sc-dashboards/dhs-cisa-binding-operational-directive-22-01
https://nucleussec.com/cisa-kev/
https://www.paloaltonetworks.com/blog/security-operations/cortex-xpanse-identify-cisa-kev/
https://blog.qualys.com/product-tech/2022/02/22/managing-cisa-known-exploited-vulnerabilities-with-qualys-vmdr
Steve's note from our Slack discussion: "I wonder if other countries have similar things. I'd hate to make it U.S. specific. I'd rather find a non-geographic way to implement this while still being able to use KEV as one of the possible feeds. "
Checklist