top | item 43705763

(no title)

tylermw | 10 months ago

MITRE is a Federally Funded Research and Development Center (FFRDC), which is a distinct type of federal contractor with strict conflict of interest regulations. They are owned by the federal government, but operated by contractors and are specifically structured and regulated to minimize conflicts of interest, so are distinct from "private industry" in many regards.

You can read a congressional report by the CRS describing FFRDCs and their role here: https://www.congress.gov/crs-product/R44629.

discuss

order

stonogo|10 months ago

MITRE is absolutely not an FFRDC. It's a regular old 501(c)(3) which happens to manage FFRDCs.

tylermw|10 months ago

Yes, you are correct, I should have typed "runs". But the point is that MITRE runs the U.S. National Cybersecurity FFRDC that maintains the CVE system, and FFRDCs are deliberately structured to minimize potential conflicts of interest (GP comment) and are definitely distinct from private industry (parent comment).

guerrilla|10 months ago

They were talking about AFTER that when it is privatized. That's what the comment they're responding to was talking about, not it's current state.