By Justin Katz Mar 10, 2021 To design a software vulnerability program for the federal government, the National Institute of Standards and Technology is reviewing work done by the Defense and Homeland Security Departments. The Internet of Things Cybersecurity Improvement Act of 2020, passed in December, tasks the NIST director with publishing guidelines for receiving, reporting, coordinating and publishing information related to security vulnerabilities -- not limited to IoT devices -- in agency systems as well as the resolving those issues. DOD published its vulnerability disclosure policy in 2016, and in September 2020 DHS issued Binding Operational Directive 20-01, “Improving Vulnerability Identification, Management, and Remediation.”