By 1 November 2025, the Secretary of Defense, the Secretary of Homeland Security and the Director of National Intelligence, with the Executive Office of the President (OSTP, the Office of the National Cyber Director and OMB), incorporate management of AI software vulnerabilities and compromises into their agencies' existing vulnerability management processes and interagency coordination mechanisms, including incident tracking, response and reporting and sharing indicators of compromise for AI systems. The duty is now sec. 5(b) of the order as amended (originally 6(e), with a 150-day deadline).
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.