In particular, as the comments set forth, while the Framework rightly recognizes that vulnerability disclosure processes are an important component of a cybersecurity program, the current framework fails to reference widely accepted standards for best practices for coordinated vulnerability disclosure. The comments urge NIST to rectify this omission to help provide clearer and more consistent guidance.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Changing Course to Get It Right: The Advisory Committee Reviews Its AI Evidence Rule
CDT is keeping a close eye on Proposed Federal Rule of Evidence 707, which would govern when AI-generated information can be admitted as evidence in federal court — and many state courts where the federal rules are routinely adopted — without a human expert to explain it.