CISA lays out new guidance for using opensource software
News Source : Help Net Security
News Summary
- The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide.
- CISA recommends treating open source software like any other software asset by assessing its security before adoption and monitoring it throughout its lifecycle.
- Agencies should choose actively maintained projects, understand the licenses governing their use, and maintain an inventory of the open-source components they depend on, the agency advises.
- The guidance recommends tracking software dependencies, monitoring projects for newly disclosed vulnerabilities, and regularly assessing whether projects remain trustworthy.
Never miss a story from us, subscribe to our newsletter