|
|
|
|
|
by smlckz
1946 days ago
|
|
> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. Understandable. > While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible program. A failure to release notification of breach to affected citizens and to patch highly-critical vulnerabilities in a timely manner reflects poorly on the state of their Information Security posture. The clock to patch vulnerabilities began immediately when the DC3 contacted the NCIIPC via Twitter, as it is a highly visible space - one which threat actors avidly monitor. Why did they published anything about the vulnerabilities before they were absolutely sure all of those has been mitigated? |
|
Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed.
An entity may not want to fix things, but at some point their users / constituents have a right to know so they can take their own protective measures.