Strategic Objective 3.3: Shift Liability for Insecure Software
Products and Services
Initiative Number: 3.3.1
Initiative Title: Explore approaches to develop a long-term, flexible, and enduring software
liability framework
Initiative Description
The Office of the National Cyber Director, working with stakeholders in academia and civil
society, will host a legal symposium to explore different approaches to a software liability
framework that draw from different areas of regulatory law and reflect inputs from computer
scientists as to the extent that software liability may or may not be like these other regimes.
NCS Reference
To begin to shape standards of care for secure software development, the Administration will
drive the development of an adaptable safe harbor framework to shield from liability companies
that securely develop and maintain their software products and services... The Administration
will work with Congress and the private sector to develop legislation establishing a liability
regime for software products and services.
Responsible Agency: ONCD
Completion Date: 2Q FY24
Initiative Number: 3.3.2
Initiative Title: Advance software bill of materials (SBOM) and mitigate the risk of
unsupported software
Initiative Description
In order to collect data on the usage of unsupported software in critical infrastructure, the
Cybersecurity and Infrastructure Security Agency will work with key stakeholders, including
SRMAs, to identify and reduce gaps in SBOM scale and implementation. CISA will also
explore requirements for a globally-accessible database for end-of-life/end-of-support software
and convene an international staff-level working group on SBOM.
NCS Reference
The Administration will .... promote the further development of SBOMs; and develop a process
for identifying and mitigating the risk presented by unsupported software that is widely used or
supports critical infrastructure.
Responsible Agency: CISA
Completion Date: 2Q FY25
30
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN