Open Source Security | CISA (2024)

Open Source Security | CISA (1)

An official website of the United States government

Here’s how you know

Open Source Security | CISA (2)

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Open Source Security | CISA (3)

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue

Search

Open Source Security | CISA (7)

Open source software is part of the foundation of the digital infrastructure we all rely upon.
Find out here how CISA is working to help secure it.

Open source software is widely used across the federal government and every critical infrastructure sector. As America’s Cyber Defense Agency, CISA works to understand and reduce cyber threats to the federal government and critical infrastructure. Ensuring secure open source software is a critical part of this effort.

CISA’s Open Source Software Security Roadmap establishes CISA’s role in helping to secure open source software by aligning it with CISA’s mission to identify and reduce risks to the federal government and critical infrastructure. In turn, CISA’s efforts will contribute to the improved security of the broader open source ecosystem.

CISA has several ongoing initiatives around open source security, including our community-driven work around software bill of materials. We also actively contribute by open sourcing much of our code via our “open-by-default” software development policy.

Open Source Security | CISA (8)

CISA Open Source Software Security Roadmap

CISA’s path forward to help ensure a secure open source ecosystem.

Learn more

Featured Content

Open Source Security | CISA (9)

Fact Sheet: Biden-⁠Harris Administration Releases Summary Report of 2023 RFI on Open Source-Software Security Initiative

On August 9, 2024, the White House, in partnership with the Open-Source Software Security Initiative, published a summary report on the Request for Information: Open-Source Software Security: Areas of Long-Term Focus and Prioritization.

Open Source Security | CISA (10)

Open Source CISA Tabletop Exercise Package (CTEP)

During the Open Source Software (OSS) Security Summit in March 2024, the participants were led through a open source tabletop exercise scenario. All organizations can use this same exercise package to assess their preparedness and response.

Open Source Security | CISA (11)

CISA Announces New Efforts to Help Secure Open Source Ecosystem

On March 5-6, CISA hosted an Open Source Software (OSS) Security Summit to develop actions and steps towards achieving a more secure open source ecosystem. To learn more, read our press release which includes a readout of the OSS Security Summit.

Open Source Security | CISA (12)

CISA GitHub

Check out CISA’s open source code on our GitHub.

Open Source Security | CISA (13)

Software Bill of Materials (SBOM)

A SBOM is a nested inventory, a list of ingredients that make up software components. CISA will advance the SBOM work by facilitating community engagement, development, and progress.

Open Source Security | CISA (14)

Enduring Security Framework Recommendations for Open Source Software and Software Bill of Materials

The Enduring Security Framework recommends practices for managing open source software and software bill of materials.

Open Source Security | CISA (15)

White House Releases End of Year Report on Open Source Software Security Initiative

On January 30, 2024, the Office of the National Cyber Director published the 2023 End of Year Report on the Open Source Software Security Initiative detailing the Administration's commitment to a safe and secure digital ecosystem.

Open Source Security | CISA (16)

CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security

CISA partners with the Open Source Security Foundation Securing Software Repositories Working Group to publish "Principles for Package Repository Security"framework which lays out voluntary security maturity levels for package repositories.

Open Source Security | CISA (17)

CISA, DHS S&T and OpenSSF Announce Global Launch of Software Supply Chain Open Source Project

CISA, in collaboration with the Open Source Security Foundation and the Department of Homeland Security Science and Technology Directorate, launched Protobom, a new and innovative open source software supply chain tool.

Open Source Security | CISA (18)

Exploring Memory Safety in Critical Open Source Projects

CISA, in partnership with the FBI, Australian Cyber Security Centre, and Canadian Cyber Security Center, crafted this joint guidance to provide organizations with findings on the scale of memory safety risk in selected open source software.

SVIP Software Artifact Dependency Graph Generation Industry Day - October 17

On Thursday, October 17, the Department of Homeland Security Science and Technology Directorate Silicon Valley Innovation Program, in partnership with CISA, is hosting an Industry Day featuring a panel discussion with experts who have worked on different parts of the software identification puzzle over the past decade, provide descriptive use cases and detailed information about the technical requirements, submission process, and resources available to startups interested in submitting applications to the Software ADG Generation Topic Call.

The event will be held in person in Menlo Park, CA and livestreamed via Zoom.

Blogs

Open Source Security | CISA (19)

Blog: With Open Source Artificial Intelligence, Don’t Forget the Lessons of Open Source Software

CISA highlights its recent work in Open Source Artificial Intelligence.

Open Source Security | CISA (20)

Blog: Continued Progress Towards a Secure Open Source Ecosystem

CISA highlights its work to across the federal government to secure Open Source Software (OSS) since it held its first Summit on OSS Security.

Open Source Security | CISA (21)

Blog: Lessons from XZ Utils: Achieving a More Sustainable Open Source Ecosystem

CISA describes how the agency has responded to the XZ Utils compromise and how every technology manufacturer can take a Secure by Design approach to securing open source software.

Open Source Security | CISA (22)

Blog: Memory Safe and Secure Coding

Director Jen Easterly stresses the importance of safe and responsible coding.

Open Source Security | CISA (23)

Blog: Open Source Software Must Start with Secure Code

CISA calls upon developers to make open source software secure from the start.

Watch Our CISA Live! on Open Source Software Security

On March 7, CISA held a CISA Live! on LinkedIn Live on open source software security. CISA’s Aeva Black,Open Source Security Section Chief, and Jack Cable, Senior Technical Advisor, discussed how CISA is collaborating with the open source community, federal partners, and the private sector to foster a more secure and resilient OSS ecosystem. This event offered participants an opportunity to learn about how CISA is working to strengthen the security of open source ecosystems, including package managers, along with ensuring the secure use of OSS within the federal government.

Contact Us

Do you have feedback on our Open Source Security work, or ideas where we can help contribute? Please share your thoughts by emailing us at: [email protected].

Open Source Security | CISA (2024)
Top Articles
Gold IRA: Should You Open One To Save For Retirement? | Bankrate
Factors, Levels and Importance of Risk Tolerance
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Dmv In Anoka
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Rogold Extension
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Weekly Math Review Q4 3
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5694

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.