Agency Readiness for Bug Bounty Programs

Ahmed Amer, with Di Cooke, Rob Lever, and Julia Pan — Aspen Tech Policy Hub, 2022 Primer Scholar cohort

Aspen Tech Policy Hub — Policy Project

A toolkit for enhancing agency preparedness for bug bounty program execution · 2022 (date approximate)

Policy Technology Policy Politics Security & critical infrastructure

Description

Bug Bounty Programs (BBPs) are an efficient and cost-effective way to improve a system’s security, allowing for scrutiny by a broader array of cybersecurity experts than a typical government agency could normally provide. Yet few agency system stakeholders understand the advantages of BBPs or are prepared to execute BBPs on their own systems. This project outlines how the Cybersecurity and Infrastructure Security Agency (CISA) could scale the use of BBPs across government by helping agencies improve their understanding of BBPs, gauge their specific agency’s readiness to execute a BBP, and prepare to execute one.

Author bio pages

Formats

Project: Read ↗ One-Pager: PDF Info Doc: PDF Score Guide: PDF Scorecard: PNG Video: Watch ↗ Cite: BIB

Cite as

@misc{amercookeleverpan2022bugbounty,
  author       = {Amer, Ahmed and Cooke, Di and Lever, Rob and Pan, Julia},
  title        = {Agency Readiness for Bug Bounty Programs: A Toolkit for Enhancing Agency Preparedness for Bug Bounty Program Execution},
  year         = {2022},
  howpublished = {Policy project, Aspen Tech Policy Hub},
  note         = {Produced as part of the Aspen Tech Policy Hub's 2022 Primer Scholar cohort. Includes a one-pager, information document, score guide, scorecard, and survey tool demo video.},
  url          = {https://www.aspentechpolicyhub.org/project/agency-readiness-for-bug-bounty-programs/}
}