Vulnerabilities Equities Process
Open-knowledge reference entry

The Vulnerabilities Equities Process (VEP) is a process used by the U.S. federal government to determine on a case-by-case basis how it should treat zero-day computer security vulnerabilities: whether to disclose them to the public to help improve general computer security, or to keep them secret for offensive use against the government's adversaries.
The VEP was first developed during the period 2008–2009, but only became public in 2016, when the government released a redacted version of the VEP in response to a FOIA request by the Electronic Frontier Foundation.
Following public pressure for greater transparency in the wake of the Shadow Brokers affair, the U.S. government made a more public disclosure of the VEP process in November 2017.
Participants
According to the VEP plan published in 2017, the Equities Review Board (ERB) is the primary forum for interagency deliberation and determinations concerning the VEP. The ERB meets monthly, but may also be convened sooner if an immediate need arises.
The ERB consists of representatives from the following agencies:
Office of Management and Budget
Office of the Director of National Intelligence (including the Intelligence Community-Security Coordination Center)
United States Department of the Treasury
United States Department of State
United States Department of Justice (including the Federal Bureau of Investigation and the National Cyber Investigative Joint Task Force)
Department of Homeland Security (including the National Cybersecurity and Communications Integration Center and the United States Secret Service)
United States Department of Energy
United States Department of Defense (to include the National Security Agency, including Information Assurance and Signals Intelligence elements), United States Cyber Command, and DoD Cyber Crime Center)
United States Department of Commerce
Central Intelligence Agency
The National Security Agency serves as the executive secretariat for the VEP.
Process
According to the November 2017 version of the VEP, the process is as follows:
Submission and notification
When an agency finds a vulnerability, it will notify the VEP secretariat as soon as is possible. The notification will include a description of the vulnerability and the vulnerable products or systems, together with the agency's recommendation to either disseminate or restrict the vulnerability information.
The secretariat will then notify all participants of the submission within one business day, requesting them to respond if they have an relevant interest.
Equity and discussions
An agency expressing an interest must indicate whether it concurs with the original recommendation to disseminate or restrict within five business days. If it does not, it will hold discussions with the submitting agency and the VEP secretariat within seven business days to attempt to reach consensus. If no consensus is reached, the participants will suggest options for the Equities Review Board.
The public source identifies “Vulnerabilities Equities Process” as open-knowledge reference entry. This brief keeps that definition visible, then builds a research path around Vulnerabilities, Equities and Process.
Why this record matters
A short description can identify a subject without explaining its stakes. For “Vulnerabilities Equities Process”, the useful work is to connect “open-knowledge reference entry” to the records capable of establishing context and consequence.
The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Sep 6, 2025. The linked authority identifier is Q48797977. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2008, 2009, 2016 and 2017.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Vulnerabilities Equities Process”, its source revision and the description used here.
- Expand the search: follow Vulnerabilities Equities Process primary sources, Vulnerabilities Equities Process archive and Vulnerabilities research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Vulnerabilities Equities Process”?
- Which institution is responsible for the underlying evidence?
- What terminology or title could unlock a more precise catalogue search?
Search terms from this dossier
This entry incorporates text from “Vulnerabilities Equities Process” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.