\
Jurisdiction
Region
Requirement
Policy
Executive Order 14028
Applies to
Software developers and vendors (specifically those that supply the federal government, but could also apply to other software developers)
Provision
Sec. 4(e)(viii)
Description
Requires NIST to issue guidance identifying practices that enhance security of the software supply chain. In the guidance NIST must include standards, procedures, or criteria related to, among other issues, "participating in a vulnerability disclosure program that includes a reporting and disclosure process."
Date
May 2021
Organization
White House