CISA lays out new guidance for using opensource software

Image for article CISA lays out new guidance for using opensource software
News Source : Help Net Security

News Summary

  • The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide.
  • CISA recommends treating open source software like any other software asset by assessing its security before adoption and monitoring it throughout its lifecycle.
  • Agencies should choose actively maintained projects, understand the licenses governing their use, and maintain an inventory of the open-source components they depend on, the agency advises.
  • The guidance recommends tracking software dependencies, monitoring projects for newly disclosed vulnerabilities, and regularly assessing whether projects remain trustworthy.

Must read Articles