< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

CISA Issues Guidance for Secure Use of Open‑Source Software by Federal Agencies

The Cybersecurity and Infrastructure Security Agency (CISA) has released a new resource titled “Open Source Software: Security Principles and Practices.” The guidance provides federal agencies with best‑practice recommendations for adopting, vetting, contributing to, and evaluating open‑source software and AI models, emphasizing the need to understand software dependencies and to manage vulnerabilities such as Log4Shell and XZ utils.

CISA advises agencies to establish formal review and approval processes, apply systematic patching, and use its C4 Framework to assess trustworthiness and risk tolerance. The guidance aligns with Executive Orders 14144 and 14306, which call for stronger cybersecurity measures across the federal government and critical‑infrastructure sectors.

Entities

Cybersecurity and Infrastructure Security Agency (CISA) · U.S. federal agencies