We the undersigned organizations, members of the Hacking Policy Council, respectfully request regulatory guidance from the Office of Foreign Assets Control (OFAC) regarding coordinated vulnerability disclosure processes and sanctions. We urge the Department to clarify organizations’ obligations when receiving a cybersecurity vulnerability disclosure from individuals in “comprehensively sanctioned” countries and regions, and the organization’s ability to ask follow-up questions regarding that vulnerability. Vulnerability disclosures are communications of information, without remuneration, performed to ensure and promote the security of information systems. We commend OFAC for stating in FAQ 448 that the “U.S. government supports efforts by researchers, cybersecurity experts, and network defense specialists to identify, respond to, and repair vulnerabilities that could be exploited by malicious actors.”1 We recognize that this is aligned with the broader U.S. government policy of reducing software vulnerabilities by promoting adoption of coordinated vulnerability disclosure processes in the public and private sectors.2It would be beneficial for OFAC to clarify that such communications from individuals in comprehensively sanctioned areas are not restricted and are exempt from sanctions.

Read Next

New Cybersecurity Executive Order, Same Mission: Protecting America's Digital Infrastructure

Since taking office speculation has swirled on what President Trump would do on cybersecurity. A new EO upholds previous messaging and underscores that cybersecurity isn't a partisan battle; it demands nonpartisan solutions to protect the nation.

Dual Drone EOs: A Boost to the Domestic Drone and Counter-Drone Industries

President Trump signed two executive orders with the stated purpose of supporting the domestic drone industry, while also protecting against the threats posed by the misuse and malicious use of drones.

Japan's new Active Cyber Defense Law: A Strategic Evolution in National Cybersecurity

Japan's National Parliament passed the landmark Active Cyber Defense Law, marking a pivotal shift in the country's cybersecurity strategy, encompassing a range of provisions aimed at modernizing Japan's institutions and enhancing cybersecurity.