 Advancing Software Security to Produce Safer Products and Services Improving software security will reduce systemic risk across the digital ecosystem. To seize this opportunity, the Federal Government has engaged with industry, academia, and civil society to promote Secure by Design principles and practices that shift the responsibility for security onto those organizations that are best positioned and most well-resourced to mitigate risk. These actions lay the groundwork for possible legislation to establish liability for cybersecurity vulnerabilities in software products and services. In April 2023, CISA released Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design, a guidance document developed with U.S. and international partners to provide organizations with concrete steps to implement Secure by Design principles. In October 2023, CISA and its partners, including eight new international agency co-sealers, published an update to the joint guidance to reflect feedback from hundreds of stakeholders. At the end of 2023, CISA also released its first Secure by Design alerts to provide guidance on secure software development practices and security defenses in technology products. In March 2024, CISA released the Secure Software Development Attestation Form, which will help ensure that the software producers who sell to the Federal Government leverage secure development techniques and toolsets. The form was drafted in consultation with OMB and based on practices established in the NIST Secure Software Development Framework. Software Bills of Material (SBOM) can enhance software supply chain risk management practices. In December 2023, NSA, ODNI, and CISA released a technical report containing guidance for industry on effective implementation of SBOM and the safe integration of opensource components into the software development lifecycle. That same month, NSA released Recommendations for Software Bills of Materials (SBOM) Management, which highlights best practices and provides recommendations for NSS to incorporate SBOM management functions suitable to their cybersecurity supply chain risk management needs. The adoption of memory safe programming languages enables the software development ecosystem to produce safer products and services. Memory safe programming languages can benefit both open-source and proprietary software and eliminate entire classes of vulnerabilities across the digital ecosystem. In December 2023, technical experts from CISA, NSA, FBI, and international partners released The Case for Memory Safe Roadmaps, containing practical guidance for organizations seeking to adopt memory safe programming languages in their environments. In February 2024, ONCD released Back to the Building Blocks: A Path Toward Secure and Measurable Software to highlight memory safety and software measurability as two security challenges that the technical community can help solve. The Federal Government has made it a priority to support the open-source developer community and enable the secure integration of open-source components. The Open-Source Software Security Initiative (OS3I) convenes public and private sector stakeholders to increase the security and resilience of the open-source software landscape. In August 2023, ONCD sought public input on open-source software security and memory safe programming languages. CISA also released an Open-Source Software Security Roadmap to prioritize its work in this space. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 21

Select target paragraph3