Public Review Period for “CNA Operational Rules” Document Open March 6–20

CVE Program Blog
2 min readMar 6, 2024

Members of the CVE community are encouraged to review and comment on the CVE Program’s new and improved “CVE Numbering Authority (CNA) Operational Rules” document. This document guides all program members on the consensus rules for CVE ID assignment, CVE Record publication and updating, and much more.

The document has already been reviewed by the CVE Board and the program’s CNA Partners. We are now making the document available for review and comment by the CVE user community.

In addition to the CNA Operational Rules document there is an Editing Process document that you should read prior to entering comments in the rules document draft. Links to both documents, as well as other details, are provided below.

Review Period

The community review period will last two (2) weeks:

  • Opens: March 06, 2024, at 11:59 p.m. ET
  • Closes: March 20, 2024, at 11:59 p.m. ET

Editing Process

All documents are provided in Google Docs. A Google account may be required to access the documents. If you are unable to use Google Docs, please contact us at cve-rules@googlegroups.com to request an alternative format.

By following the instructions in the Editing Process document, you will enhance our ability to expedite organizing, reviewing, and addressing all collected comments. Please read the Editing Process document prior to reviewing the CNA Operational Rules document.

The “Editing Process” document is located here.

Rules Document for Review and Comment

The “CNA Operational Rules” document, which will only be accessible during the review period, is located here.

To review only selected highlights of changes from the previous version of the document, click here.

Final Publication

This is the first major revision of the CNA Operational Rules that will explicitly include public input. We expect to learn from this revision process and develop a more robust and repeatable process for future revisions of the CNA Operational Rules and other CVE Program documents.

The final version of the document will be published later in 2024.

--

--

CVE Program Blog

The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. https://www.cve.org