Advancing Software Security to Produce Safer Products and Services
Improving software security will reduce systemic risk across the digital ecosystem. To seize this
opportunity, the Federal Government has engaged with industry, academia, and civil society to
promote Secure by Design principles and practices that shift the responsibility for security onto
those organizations that are best positioned and most well-resourced to mitigate risk. These
actions lay the groundwork for possible legislation to establish liability for cybersecurity
vulnerabilities in software products and services.
In April 2023, CISA released Shifting the Balance of Cybersecurity Risk: Principles and
Approaches for Secure by Design, a guidance document developed with U.S. and international
partners to provide organizations with concrete steps to implement Secure by Design principles.
In October 2023, CISA and its partners, including eight new international agency co-sealers,
published an update to the joint guidance to reflect feedback from hundreds of stakeholders. At
the end of 2023, CISA also released its first Secure by Design alerts to provide guidance on
secure software development practices and security defenses in technology products.
In March 2024, CISA released the Secure Software Development Attestation Form, which will
help ensure that the software producers who sell to the Federal Government leverage secure
development techniques and toolsets. The form was drafted in consultation with OMB and
based on practices established in the NIST Secure Software Development Framework.
Software Bills of Material (SBOM) can enhance software supply chain risk management
practices. In December 2023, NSA, ODNI, and CISA released a technical report containing
guidance for industry on effective implementation of SBOM and the safe integration of opensource components into the software development lifecycle. That same month, NSA released
Recommendations for Software Bills of Materials (SBOM) Management, which highlights best
practices and provides recommendations for NSS to incorporate SBOM management functions
suitable to their cybersecurity supply chain risk management needs.
The adoption of memory safe programming languages enables the software development
ecosystem to produce safer products and services. Memory safe programming languages can
benefit both open-source and proprietary software and eliminate entire classes of vulnerabilities
across the digital ecosystem. In December 2023, technical experts from CISA, NSA, FBI, and
international partners released The Case for Memory Safe Roadmaps, containing practical
guidance for organizations seeking to adopt memory safe programming languages in their
environments. In February 2024, ONCD released Back to the Building Blocks: A Path Toward
Secure and Measurable Software to highlight memory safety and software measurability as two
security challenges that the technical community can help solve.
The Federal Government has made it a priority to support the open-source developer community
and enable the secure integration of open-source components. The Open-Source Software
Security Initiative (OS3I) convenes public and private sector stakeholders to increase the security
and resilience of the open-source software landscape. In August 2023, ONCD sought public
input on open-source software security and memory safe programming languages. CISA also
released an Open-Source Software Security Roadmap to prioritize its work in this space.
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
21