The National Institute of Standards and Technology is angling to modernize how it reports and responds to cyber vulnerabilities with the help of artificial intelligence. #
The National Institute of Standards and Technology is looking to augment its central repository of digital vulnerabilities with help from artificial intelligence.
In a new Request for Information published in the Federal Register on Wednesday, NIST said it is seeking input surrounding how to best modernize its National Vulnerability Database by leveraging AI to enhance how the agency documents and responds to identified cybersecurity weaknesses.
The NVD documents digital vulnerabilities, cataloguing their severity, impacted products and other relevant data. Some of the challenges to modernization the RFI seeks to address include growth in both the number and complexity of newly disclosed vulnerabilities, a diverse range in data quality, a reliance on automation and machine-readable security data and the emergence of AI-assisted vulnerability discovery.
“The advancement of AI presents an opportunity to transform the vulnerability management ecosystem,” the document reads. “This requires input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats.”
The RFI seeks feedback to better understand how AI tools can improve the broad vulnerability management lifecycle and ecosystem, enhance risk assessment efforts and better remediate vulnerabilities.
NIST is also looking to learn more about what, if any, changes need to be made to existing organizational structures and standards to improve both the data quality and procedural handling of vulnerabilities.
Rapid advancements in AI technology and its impact –– both as an asset and adversary –– on cybersecurity has been a paramount tech policy issue, reaching a climax after models from both OpenAI and Anthropic escaping containment environments. Prior to these incidents, the White House had turned its attention to addressing the cybersecurity impacts of AI, including multiple cybersecurity action items in a June executive order.
As part of the EO, the Trump administration created an AI-supported vulnerability clearinghouse within the new Gold Eagle initiative. Gold Eagle is primarily a coordinated vulnerability sharing effort. A NIST spokesperson told *Nextgov/FCW *that its effort to modernize the NVD is not related to any recent executive action.
“Our RFI is not in response to any specific executive orders or to the Gold Eagle Initiative,” the spokesperson said. “However, we expect that tools like the NVD will continue to play an important role in the broader vulnerability management and coordination ecosystem.”