CISA aims to make executives sign off on security of software sold to government

Published: Nov. 22, 2023, 12:52 p.m.

The Cybersecurity and Infrastructure Security Agency is attempting to make cybersecurity a high-level issue for companies by only allowing top executives to sign off on a new secure software attestation form that will be used across the federal government.\nCISA released the second draft of the \u201csecure software development attestation form\u201d this week after releasing an initial version of the form in April. The form is a key component in a government-wide push to ensure agencies use securely developed software. The attestation\u2019s form\u2019s requirements are based on the National Institute of Standards and Technology\u2019s Secure Software Development Framework (SSDF).\nThe latest version of the form is now open for comment to CISA and the White House Office of Management and Budget through Dec. 18. Once the form is finalized, OMB will require agencies to start using the form within three months for all \u201ccritical software\u201d and six months for most other third-party software.\nLearn more about your ad choices. Visit podcastchoices.com/adchoices