CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

Vulnerabilities Equities Process

Open-knowledge reference entry

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionSep 6, 2025
Entity authorityQ48797977
Source-derived summary

The Vulnerabilities Equities Process (VEP) is a process used by the U.S. federal government to determine on a case-by-case basis how it should treat zero-day computer security vulnerabilities: whether to disclose them to the public to help improve general computer security, or to keep them secret for offensive use against the government's adversaries.

The VEP was first developed during the period 2008–2009, but only became public in 2016, when the government released a redacted version of the VEP in response to a FOIA request by the Electronic Frontier Foundation.

Following public pressure for greater transparency in the wake of the Shadow Brokers affair, the U.S. government made a more public disclosure of the VEP process in November 2017.

Participants

According to the VEP plan published in 2017, the Equities Review Board (ERB) is the primary forum for interagency deliberation and determinations concerning the VEP. The ERB meets monthly, but may also be convened sooner if an immediate need arises.

The ERB consists of representatives from the following agencies:

Office of Management and Budget

Office of the Director of National Intelligence (including the Intelligence Community-Security Coordination Center)

United States Department of the Treasury

United States Department of State

United States Department of Justice (including the Federal Bureau of Investigation and the National Cyber Investigative Joint Task Force)

Department of Homeland Security (including the National Cybersecurity and Communications Integration Center and the United States Secret Service)

United States Department of Energy

United States Department of Defense (to include the National Security Agency, including Information Assurance and Signals Intelligence elements), United States Cyber Command, and DoD Cyber Crime Center)

United States Department of Commerce

Central Intelligence Agency

The National Security Agency serves as the executive secretariat for the VEP.

Process

According to the November 2017 version of the VEP, the process is as follows:

Submission and notification

When an agency finds a vulnerability, it will notify the VEP secretariat as soon as is possible. The notification will include a description of the vulnerability and the vulnerable products or systems, together with the agency's recommendation to either disseminate or restrict the vulnerability information.

The secretariat will then notify all participants of the submission within one business day, requesting them to respond if they have an relevant interest.

Equity and discussions

An agency expressing an interest must indicate whether it concurs with the original recommendation to disseminate or restrict within five business days. If it does not, it will hold discussions with the submitting agency and the VEP secretariat within seven business days to attempt to reach consensus. If no consensus is reached, the participants will suggest options for the Equities Review Board.

Editorial summary

The public source identifies “Vulnerabilities Equities Process” as open-knowledge reference entry. This brief keeps that definition visible, then builds a research path around Vulnerabilities, Equities and Process.

Editorial reviewA concise reference frame for defining the subject, testing terminology and identifying the institution closest to the evidence. The current lead gives the account dated anchors—2008, 2009, 2016, 2017—that can be checked directly. The selected authority fields contribute no independent date. Its value is orientation rather than verdict, with Vulnerabilities, Equities and Process providing the first useful test.
Editorial analysis

Why this record matters

A short description can identify a subject without explaining its stakes. For “Vulnerabilities Equities Process”, the useful work is to connect “open-knowledge reference entry” to the records capable of establishing context and consequence.

Evidence profile

The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Sep 6, 2025. The linked authority identifier is Q48797977. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2008, 2009, 2016 and 2017.

Critical limits

A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “Vulnerabilities Equities Process”, its source revision and the description used here.
  2. Expand the search: follow Vulnerabilities Equities Process primary sources, Vulnerabilities Equities Process archive and Vulnerabilities research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Vulnerabilities Equities Process”?
  2. Which institution is responsible for the underlying evidence?
  3. What terminology or title could unlock a more precise catalogue search?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from Vulnerabilities Equities Process” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.