Trump administration publishes inter-agency rules for disclosing or keeping secret cyber security flaws, with decisions to retain flaws being revisited annually
Dustin Volz / Reuters :
Context & Ripple Effects
This rule lands mid-arc: Barack Obama had already pushed an executive order directing government and companies to share more threat information in 2015, and a December 2016 White House study handed the incoming administration a set of recommendations to implement. Donald Trump's May 2017 executive order reviewing federal cybersecurity largely kept the prior two administrations' policy path, and these inter-agency rules are the first concrete structure to come out of that posture.
What changed today is procedural: the disclose-or-withhold decision for discovered software flaws moves from ad hoc judgment into a published inter-agency process, with any decision to keep a flaw secret revisited every year rather than held indefinitely.
First-order effects
- Agencies holding discovered vulnerabilities — intelligence and defense arms chief among them — must now document and annually re-justify why a flaw stays undisclosed instead of being reported to vendors for patching.
- Software vendors and security researchers get a defined, published pathway for how government-discovered flaws reach them, replacing an opaque internal practice with rules they can at least see.
Second-order effects
- The disclosure framework sits uneasily beside the same administration's later move to loosen restrictions on offensive operations by reversing classified Obama-era cyberweapon rules — one hand codifying when flaws get patched, the other expanding the incentive to stockpile them.
- Downstream, DHS built directly on this disclosure logic with its 2020 mandate requiring federal agencies to run vulnerability disclosure programs, extending the principle from government-held flaws to all internet-accessible agency systems.
Third-order effects
- If the pattern holds, the equities question — patch versus weaponize — becomes permanent bureaucratic machinery that each administration inherits and re-tunes rather than relitigates, with successors like Biden's push for voluntary cybersecurity goals for critical-infrastructure operators layering further obligations on top.
- Annual revisit requirements create a structural bias toward eventual disclosure: a retained flaw needs a fresh justification every year, which over time shifts the default from indefinite stockpiling toward reporting.
The trend: US cyber policy is converging on formalized, reviewable processes for handling dual-use vulnerabilities even as each successive administration adjusts the balance between defensive disclosure and offensive stockpiling.