[Podcast] CVE Numbering, Governance, and Advocacy with Katie Trimble and Chris Coffin

[Podcast] CVE Numbering, Governance, and Advocacy with Katie Trimble and Chris Coffin

On this week’s episode of Security Nation, we had the pleasure of speaking with Katie Trimble of the Department of Homeland Security and Chris Coffin from MITRE. Katie is the deputy branch chief of the Vulnerability Management Coordination Disclosures Branch within the Cyber and Infrastructure Security Agency (CISA)—say that five times fast!—and Chris is the senior analyst on the CVE team at MITRE Corporation, a not-for-profit organization that runs federally funded research and development centers (FFRDCs).


Our podcast highlights guests who have taken on a challenge that has advanced security in some way, and Katie and Chris’s work with the CVE Project is a perfect example of this. You can listen to the full episode here, or read our recap below!

Vulnerabilities, CVEs, and NIST: Katie’s portfolio


As Katie explained in the podcast, she is responsible for the coordination of vulnerability disclosures within the department. She manages four portfolios, one of which is the Common Vulnerability and Exposures program operated by MITRE. She sits on the CVE Board of Directors and is the government sponsor of that program. She also sponsors the NIST National Vulnerability Database (NVD) program, as well as the Carnegie Mellon Software Engineering Institute CERT Coordination Center. To say she keeps busy is an understatement!


Katie joined the CISA in October 2017 to centralize all of its disparate portfolios. At the time, the organization had one person out in Idaho managing ICS, another in her office doing CVE work, and so on. Katie ..

Support the originator by clicking the read the rest link below.