Sophos Named Common Vulnerability and Exposure Numbering Authority

Sophos Press Release

OXFORD, U.K. – Jan. 13, 2021 – Sophos, a global leader in next-generation cybersecurity, today announced that it has been named a Common Vulnerabilities and Exposures (CVE) Numbering Authority (CNA) in the CVE program, a recognized international standard for identifying and naming cybersecurity vulnerabilities. With this status, Sophos is authorized to assign CVE identification to unique vulnerabilities within the scope of its products. Security researchers can now work directly with Sophos to open CVEs for the company’s products, making the process of reporting issues and assigning CVEs more straightforward.

The CVE program is an international, community-based effort that maintains a community-driven, open data registry of vulnerabilities. The program catalogs CVEs in a publicly available registry that is available to security researchers, vulnerability disclosers and information technology vendors. Using a common identifier makes it easier to share and cross-check data across the industry’s several and separate security databases and tools that track vulnerabilities.

“Sophos’ new status as a CNA is another example of our commitment to be transparent, and by having the ability to assign CVEs, we can provide the industry with pertinent information about our products faster. This allows organizations to more quickly assess security issues, determine the scale of urgency and prioritize updates,” said Ross McKerchar, vice president and chief information security officer at Sophos. “Sophos’ CVEs will also get entered into the multiple CVE-compatible databases within the industry. By working collectively on these databases with other vendors and industry standards watchguards, we can together improve defenses against persistent attackers.”

“The Common Vulnerabilities and Exposures Team welcomes Sophos as our newest CVE Numbering Authority. Sophos has a strong reputation of contributing to the global digital security community, producing antivirus, encryption and cybersecurity capabilities for over 30 years. Their experience brings real value to the CVE Program. We are very pleased to have Sophos as a contributing member of the CVE Team,” said Kent Landfield, CVE board member.

About the CVE Program
Common Vulnerabilities and Exposures (CVE®) is an international, community-based effort that maintains a community-driven, open data registry of vulnerabilities. The CVE IDs assigned through the registry enable program stakeholders to rapidly discover and correlate vulnerability information used to protect systems against attacks. The CVE Program currently has 149 CNA’s in 25 countries, globally across technologies and services.

ソフォスについて

次世代型サイバーセキュリティにおいて世界をリードする企業としてソフォスは、世界 150ヶ国以上、 40万社を超えるあらゆる規模の組織を今日の高度なサイバー脅威から保護します。グローバルに展開する脅威解析およびデータサイエンスチームである SophosLabs を活用することで、 クラウドネイティブと AI 機能強化ソリューションは、エンドポイント (ノート PC、サーバー、モバイルデバイス) およびランサムウェア、マルウェア、エクスプロイト、データ窃取、アクティブな攻撃による侵害、フィッシングなど進化するサイバー攻撃の技術に対抗してネットワークを保護します。Sophos Central は、クラウドネイティブの管理プラットフォームで、Intercept X エンドポイントソリューションや XG 次世代型ファイアウォールなどの次世代製品のポートフォリオ全体を API セットを介してアクセス可能な単一の「Synchronized Security」システムに統合します。ソフォスは、クラウド、機械学習、API、自動化、MTR (Managed Threat Response) などの高度な機能を活用して、あらゆる規模の組織にエンタープライズクラスの保護を提供することで、次世代型サイバーセキュリティへ移行を推進しています。ソフォスは、 世界各地の 53,000社を超えるチャネルパートナーとマネージドサービスプロバイダー (MSP) を通じて、当社の製品とサービスを独占販売しています。ソフォスはまた Sophos Home を通じて革新的な商業用技術を消費者に提供しています。本社は英国オックスフォードにあります。詳細については www.sophos.com をご覧ください。