diff --git a/Inactive_CNA_Policy.md b/Inactive_CNA_Policy.md index abcc882..9be536a 100644 --- a/Inactive_CNA_Policy.md +++ b/Inactive_CNA_Policy.md @@ -1,84 +1,85 @@ -# CVE Program Policy and Procedure for Inactive CNAs +# CVE Policy for Inactive CNAs -| Status | Final | -| ---: | --- | -| Version | 1.2.0 | -| Approved | 2021-01-14 | -| Effective | 2021-01-14 | +Document Version: 2.0.0 -## Policy for Inactive CNAs +CVE Board Approval: Month xx, 2026 -This policy and procedure is enforceable by Roots and the Secretariat. +Effective Date: Month xx, 2026 -Active CNA participation is critical for the CVE Program to achieve its adoption, coverage, and time-to-populate goals. Active CNAs assign CVE IDs and publish CVE Records within a distinct, agreed upon, and documented scope (hereafter referred to as scope). By assigning CVE IDs and publishing CVE Records, CNAs expand CVE Program coverage and adoption, and are critical actors in federating CVE Program operations. Active CNAs may also participate in various working groups and discussions to advance CVE Program objectives. +## Purpose and Scope -Inactive CNAs may be problematic for the CVE Program because adoption and coverage may not be achieved within a scope, even though such a scope is assigned to a CNA. However, inactive CNAs may be inactive for legitimate reasons, such as no new vulnerabilities are identified within a scope and, once identified, normal assignment and publication activities are resumed. There are also illegitimate reasons for CNA inactivity, such as the CNA is no longer interested, properly resourced, or competent to participate in the CVE Program as a CNA. CNAs that are inactive for legitimate reasons may continue to participate in the CVE Program. CNAs that are inactive for illegitimate reasons may not continue to participate in the CVE Program, unless the reasons for inactivity are satisfactorily remediated. +The effectiveness of the CVE Program’s federated model depends on active [CVE Numbering +Authority (CNA)](https://www.cve.org/ResourcesSupport/Glossary#glossaryCNA) participation to preserve program coverage, accountability, and operational +continuity. -Inactive CNAs are identified as those CNAs, over the preceding six-month period, that have not assigned CVE IDs or published CVE Records within a scope, and have not participated in any of the various working groups and discussions to advance CVE Program objectives. +This policy defines how the CVE Program identifies and addresses inactive CNAs. It is +enforceable by CVE Program [Roots](https://www.cve.org/ResourcesSupport/Glossary#glossaryRoot), [TL-Roots](https://www.cve.org/ResourcesSupport/Glossary#glossaryTLRoot), and the [Secretariat](https://www.cve.org/ResourcesSupport/Glossary#glossarySecretariat). -Inactive CNAs must be identified by their Root CNA so that: 1) the reason(s) for inactivity are determined; and 2) appropriate next steps are taken. +This policy applies to all CNAs operating under any Root within the CVE Program. -## Procedure for Contacting Inactive CNAs +## Inactive CNA Identification -1. Attempt to contact the CNA using all available contact information to determine the reason(s) for the inactivity and appropriate next steps; use the following message: +A CNA is considered inactive when, over six months (or another period defined in writing by its +TL-Root or Root), the CNA: - > Active participation in the CVE Program is necessary to retain CNA status. Our records indicate that is currently inactive (i.e., over the preceding six-month period, CNA has not assigned CVE IDs or publish CVE Records within a scope, and/or has not participated in various working groups and discussions to advance CVE Program objectives). Please let us know the reasons for the inactivity by . +* Has not assigned or reserved CVE IDs within its scope; or - If contact is made within two weeks, follow the [Reason for Inactivity](https://www.cve.org/Resources/General/Policies/Inactive-CNA-Policy.pdf#page=3&zoom=100,92,580) instructions. If contact is not made, proceed to step 2. -2. Two weeks after taking step 1, attempt to contact the CNA again (replying to the email submission from step 1) using the following message: +* Has not published any CVE Records within its scope; or - > The CVE Program contacted you on to determine the reason for inactivity. Active participation in the CVE Program is necessary to maintain CNA status. Please let us know the reasons for the inactivity by . We look forward to hearing from you soon. +* Has not participated in working groups or discussions to advance CVE Program +objectives; or -If contact is made within two weeks, follow the Reason for Inactivity instructions. If contact is not made, proceed to step 3. +* Fails to respond to inquiries or requests from its Root, TL-Root, or the Secretariat. -3. If contact is not made within two weeks of the step 2 communication, warn the CNA that it will be removed from the CVE Program within two weeks if they do not respond (replying to the email string from step 2); use the following statement: +The mere presence of reserved CVE IDs, if they have extraordinarily long disclosure +timeframes, is not considered a sign of activity (see the CVE Reserved but Public (RBP) Policy). - > The CVE Program contacted you on to determine the reason for inactivity. Our records indicate that is currently inactive because . Active participation in the CVE Program is necessary to maintain CNA status. If the CVE Program does not hear from you by , your CNA status will be revoked, which means that will no longer be authorized to assign CVE IDs or populate CVE Records and will be removed from the CNA roster, CNA-specific communication, and applicable working groups. - > - > Should your CNA status be revoked, you are eligible to reapply to become a CNA in the future, provided you complete the CNA onboarding process. - > - > We look forward to hearing from you soon. +## Reasons for Inactivity -If contact is made within two weeks, follow the Reason for Inactivity instructions. If contact is not made, proceed to step 4 +The CVE Program considers some reasons for inactivity to be valid, for instance, when no new +vulnerabilities have been identified within the CNA’s scope and normal assignment and +publication activities resume once vulnerabilities are identified. -4. Two weeks after step 3, if contact is not made with the CNA, inform the CNA that its CNA status is hereby revoked respond (replying to the email string from step 3), using the following statement: +The CVE Program considers other reasons for inactivity to be invalid, for instance: - > The CVE Program contacted on to determine why is inactive within the CVE Program. Responses to those communications were not received. Per the last communication, sent on CNA status is hereby revoked. This means that is no longer authorized to assign CVE IDs or publish CVE Records and has been removed from the CNA roster, CNA-specific communication, and applicable working groups. - > - > \ is eligible to reapply to become a CNA should the organization’s circumstances change. Should want to be a CNA in the future, please contact . - > - > Thank you for past service to the CVE Program. +* When the CNA is no longer interested, properly resourced, or competent to participate in the +CVE Program as a CNA. -6. The next step is to follow the CVE Program’s CNA Removal Process to remove the organization as a CNA. +* When the CNA’s actions are detrimental to CVE Program objectives, for example, publishing +vulnerability records exclusively through a platform outside of the CVE Program (such as a +separate vulnerability information initiative). -## Reason for Inactivity +CNAs that are inactive for valid reasons may continue to participate in the CVE Program. CNAs +that are inactive for invalid reasons may not continue to participate, unless the reasons for +inactivity are remediated to the satisfaction of the Root. -1. No longer wants to participate: Follow the [CNA Removal Process](https://www.cve.org/Resources/General/Policies/Inactive-CNA-Policy.pdf#page=3&zoom=100,92,712). +## Identification and Engagement of Inactive CNAs -2. Legitimate: Document the reason(s) for inactivity and notify the Secretariat, the other Roots, and the CVE Board. +Roots and TL-Roots are responsible for identifying potentially inactive CNAs within their +hierarchies and taking appropriate follow-up actions. -3. Illegitimate: Document the reason(s) for inactivity and any corrective action that may be required. Notify the Secretariat, the other Roots, and the CVE Board. +When a CNA appears to be inactive, the Root or TL-Root should: -## Secretariat-specific CNA Removal Process +1. Attempt to contact the CNA using the Administrative Point of Contact and any other +available contact information to + * Confirm CNA communication status; + * Determine the reason(s) for inactivity (valid or invalid); and + * Discuss appropriate next steps, including remediation or possible +decertification and removal from the program -1. Announce the revocation of the CNA’s status: +2. Provide the CNA a reasonable timeframe (as defined by the TL-Root or Root) to respond +and, if appropriate, to propose or implement corrective actions. - a. Send an email to the private CVE Board list. +## Decertified CNAs -2. Notify Web Admin so that the CNA is removed from the CNA list on the website (). - -3. Mark the CNA as inactive in the CVE Wiki. - -4. Transition the CNA’s CVE IDs to another CNA: - - a. Reject all of the CNA’s reserved but not public IDs. - - b. Transfer responsibility to the appropriate CNA(s) for the remaining CVE IDs. - -5. Revoke the CNA’s privileges to all systems. - - a. Ask Content Team to mark CNA as inactive in the CPS. - - b. Remove CNA from the CNA mailing list (Only do this after the revocation message is sent). - - c. Ask the Content Team to remove the CNA from the authorized GitHub contributors. +A CNA that is decertified: +* Is no longer authorized to assign CVE IDs or publish CVE Records within a defined +scope +* Will be removed from the CVE-Services, CNA-specific communications lists, and the +[List of Partners](https://www.cve.org/PartnerInformation/ListofPartners) on the cve.org website. +* Will be mentioned in a public notification on the [CVE.org](http://cve.org/) website from the Root +announcing the decertification along with the background and justification for the +decertification. +* Will be announced to the CNA mailing list. +CNAs that are decertified are eligible to reapply to become a CNA in the future. They must +complete the CNA onboarding process again and meet all current Program requirements.