{"id":1389,"date":"2018-04-24T07:59:19","date_gmt":"2018-04-24T15:59:19","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=1389"},"modified":"2018-05-03T07:40:52","modified_gmt":"2018-05-03T15:40:52","slug":"mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/","title":{"rendered":"Mozilla publishes recommendations on government vulnerability disclosure in Europe"},"content":{"rendered":"<p><b><i>A<\/i>s we\u2019ve argued on <\/b><a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/10\/03\/vulnerability-disclosure-should-be-in-new-eu-cybersecurity-strategy\/\"><b>many occasions<\/b><\/a><b>, effective government vulnerability disclosure (GVD) review processes can greatly enhance cybersecurity for governments, citizens, and companies, and help mitigate risk in an ever-broadening cyber threat landscape. \u00a0In Europe, the EU is currently discussing a new legislative proposal to enhance cybersecurity across the bloc, the so-called \u2018EU Cybersecurity Act\u2019. In that context, we\u2019ve just published our <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2018\/04\/Mozilla_EU-Cybersecurity-Act_Position-paper.pdf\">policy recommendations<\/a> <\/b><b>for lawmakers, in which we call on the EU to seize the opportunity to set a global policy norm for government vulnerability disclosure. \u00a0<\/b><\/p>\n<p>Specifically, <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2018\/04\/Mozilla_EU-Cybersecurity-Act_Position-paper.pdf\">our policy recommendations<\/a>\u00a0for lawmakers focus predominantly on the elements of the legislative proposal that concern the enhanced mandate for ENISA (the EU Cybersecurity agency), namely articles three to eleven. Therein, we recommend the EU co-legislators to include within ENISA\u2019s reformed responsibilities a mandate to assist Member States in establishing and implementing \u00a0policies and practices for the responsible management and coordinated disclosure of vulnerabilities in ICT products and services that are not publicly known.<\/p>\n<p>As the producer of one of the world\u2019s most popular web browsers, it is essential for us that vulnerabilities in our software are quickly identified and patched. Simply put, the safety and security of our users depend on it. More broadly, as witnessed in the recent <a href=\"https:\/\/securingtomorrow.mcafee.com\/consumer\/consumer-threat-notices\/petya-ransomware\/\">Petya,<\/a> and <a href=\"https:\/\/www.symantec.com\/blogs\/threat-intelligence\/wannacry-ransomware-attack\">WannaCry<\/a> cyberattacks, vulnerabilities can be exploited by cybercriminals to cause serious damage to citizens, enterprises, public services, and governments.<\/p>\n<p>Vulnerability disclosure (and the processes that underpin it) is particularly important with respect to governments. Governments often have unique knowledge of vulnerabilities, and learn about vulnerabilities in many ways: through their own research and development, by purchasing them, through intelligence work, or by reports from third parties. Crucially, governments can face conflicting incentives as to whether to disclose the existence of such vulnerabilities to the vendor immediately, or to delay disclosure in order to support offensive intelligence-gathering and law enforcement activities (so-called government hacking).<\/p>\n<p>In both the US and the EU, Mozilla has long led calls for governments to codify and improve their policies and processes for handling vulnerability disclosure, including<a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2017\/05\/17\/working-together-towards-secure-internet-vep-reform\/\"> speaking out<\/a> strongly in favor of the Protecting Our Ability to Counter Hacking Act (<a href=\"https:\/\/www.schatz.senate.gov\/imo\/media\/doc\/BAG17434_FINAL%20PATCH.pdf\">PATCH Act)<\/a> in the United States. Mozilla is also a member of the <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2018\/04\/CEPS-Draft-Recommendations-Flyer.pdf\">Centre for European Policy Studies&#8217; Task Force on Software Vulnerability Disclosure<\/a>, a multistakeholder effort dedicated to advancing thinking on this important topic, including mapping current practices and developing a model for government vulnerability disclosure review. We strongly believe that by putting in place such frameworks, governments can contribute to greater cybersecurity for their citizens, their businesses, and even themselves.<\/p>\n<p>As our <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2018\/04\/Mozilla_EU-Cybersecurity-Act_Position-paper.pdf\">policy recommendation<\/a> contends, the proposed EU Cybersecurity Act offers a unique opportunity to advance the norm that Member States should have robust, accountable, and transparent government vulnerability disclosure review processes, thereby fostering greater cybersecurity in Europe. Indeed, through its capacity to assist and advise on the development of policy and practices, a reformed ENISA is well-placed to support the EU Member States in developing government vulnerability disclosure review mechanisms and sharing best practices.<\/p>\n<p>Over the coming months, we\u2019ll be working closely with EU lawmakers to explain this issue and highlight its importance for cybersecurity in Europe.<\/p>\n<p>If you\u2019re interested in reading our recommendations in full, you can access them <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2018\/04\/Mozilla_EU-Cybersecurity-Act_Position-paper.pdf\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we\u2019ve argued on many occasions, effective government vulnerability disclosure (GVD) review processes can greatly enhance cybersecurity for governments, citizens, and companies, and help mitigate risk in an ever-broadening cyber &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/\">Read more<\/a><\/p>\n","protected":false},"author":1559,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[283198,283226,847,10127,69,10136],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla recommendations on government vulnerability disclosure in the EU<\/title>\n<meta name=\"description\" content=\"Government vulnerability disclosure mechanisms are a key tool in enhancing cybersecurity for citizens, business, and governments. We&#039;ve just published policy recommendations for EU lawmakers on how to set a global policy norm in this space.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Owen Bennett\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/\",\"name\":\"Mozilla recommendations on government vulnerability disclosure in the EU\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2018-04-24T15:59:19+00:00\",\"dateModified\":\"2018-05-03T15:40:52+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63\"},\"description\":\"Government vulnerability disclosure mechanisms are a key tool in enhancing cybersecurity for citizens, business, and governments. We've just published policy recommendations for EU lawmakers on how to set a global policy norm in this space.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla publishes recommendations on government vulnerability disclosure in Europe\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63\",\"name\":\"Owen Bennett\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/e46a666e0d8a768b13461b5a1539a34a\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g\",\"caption\":\"Owen Bennett\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla recommendations on government vulnerability disclosure in the EU","description":"Government vulnerability disclosure mechanisms are a key tool in enhancing cybersecurity for citizens, business, and governments. We've just published policy recommendations for EU lawmakers on how to set a global policy norm in this space.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/","twitter_misc":{"Written by":"Owen Bennett","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/","name":"Mozilla recommendations on government vulnerability disclosure in the EU","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2018-04-24T15:59:19+00:00","dateModified":"2018-05-03T15:40:52+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63"},"description":"Government vulnerability disclosure mechanisms are a key tool in enhancing cybersecurity for citizens, business, and governments. We've just published policy recommendations for EU lawmakers on how to set a global policy norm in this space.","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2018\/04\/24\/mozilla-publishes-recommendations-on-government-vulnerability-disclosure-in-europe\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Mozilla publishes recommendations on government vulnerability disclosure in Europe"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63","name":"Owen Bennett","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/e46a666e0d8a768b13461b5a1539a34a","url":"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g","caption":"Owen Bennett"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1389"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1559"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=1389"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1389\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=1389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=1389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=1389"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=1389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}