Open Source Security | CISA (2024)

Open Source Security | CISA (1)

An official website of the United States government

Here’s how you know

Open Source Security | CISA (2)

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Open Source Security | CISA (3)

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber Services#protect2024Secure Our WorldShields UpReport A Cyber Issue

Search

Open Source Security | CISA (7)

Open source software is part of the foundation of the digital infrastructure we all rely upon.
Find out here how CISA is working to help secure it.

Open source software is widely used across the federal government and every critical infrastructure sector. As America’s Cyber Defense Agency, CISA works to understand and reduce cyber threats to the federal government and critical infrastructure. Ensuring secure open source software is a critical part of this effort.

CISA’s Open Source Software Security Roadmap establishes CISA’s role in helping to secure open source software by aligning it with CISA’s mission to identify and reduce risks to the federal government and critical infrastructure. In turn, CISA’s efforts will contribute to the improved security of the broader open source ecosystem.

CISA has several ongoing initiatives around open source security, including our community-driven work around software bill of materials. We also actively contribute by open sourcing much of our code via our “open-by-default” software development policy.

Open Source Security | CISA (8)

CISA Open Source Software Security Roadmap

CISA’s path forward to help ensure a secure open source ecosystem.

Learn more

Featured Content

Open Source Security | CISA (9)

Fact Sheet: Biden-⁠Harris Administration Releases Summary Report of 2023 RFI on Open Source-Software Security Initiative

On August 9, 2024, the White House, in partnership with the Open-Source Software Security Initiative, published a summary report on the Request for Information: Open-Source Software Security: Areas of Long-Term Focus and Prioritization.

Open Source Security | CISA (10)

Open Source CISA Tabletop Exercise Package (CTEP)

During the Open Source Software (OSS) Security Summit in March 2024, the participants were led through a open source tabletop exercise scenario. All organizations can use this same exercise package to assess their preparedness and response.

Open Source Security | CISA (11)

CISA Announces New Efforts to Help Secure Open Source Ecosystem

On March 5-6, CISA hosted an Open Source Software (OSS) Security Summit to develop actions and steps towards achieving a more secure open source ecosystem. To learn more, read our press release which includes a readout of the OSS Security Summit.

Open Source Security | CISA (12)

CISA GitHub

Check out CISA’s open source code on our GitHub.

Open Source Security | CISA (13)

Software Bill of Materials (SBOM)

A SBOM is a nested inventory, a list of ingredients that make up software components. CISA will advance the SBOM work by facilitating community engagement, development, and progress.

Open Source Security | CISA (14)

Enduring Security Framework Recommendations for Open Source Software and Software Bill of Materials

The Enduring Security Framework recommends practices for managing open source software and software bill of materials.

Open Source Security | CISA (15)

White House Releases End of Year Report on Open Source Software Security Initiative

On January 30, 2024, the Office of the National Cyber Director published the 2023 End of Year Report on the Open Source Software Security Initiative detailing the Administration's commitment to a safe and secure digital ecosystem.

Open Source Security | CISA (16)

CISA Partners With OpenSSF Securing Software Repositories Working Group to Release Principles for Package Repository Security

CISA partners with the Open Source Security Foundation Securing Software Repositories Working Group to publish "Principles for Package Repository Security"framework which lays out voluntary security maturity levels for package repositories.

Open Source Security | CISA (17)

CISA, DHS S&T and OpenSSF Announce Global Launch of Software Supply Chain Open Source Project

CISA, in collaboration with the Open Source Security Foundation and the Department of Homeland Security Science and Technology Directorate, launched Protobom, a new and innovative open source software supply chain tool.

Open Source Security | CISA (18)

Exploring Memory Safety in Critical Open Source Projects

CISA, in partnership with the FBI, Australian Cyber Security Centre, and Canadian Cyber Security Center, crafted this joint guidance to provide organizations with findings on the scale of memory safety risk in selected open source software.

SVIP Software Artifact Dependency Graph Generation Industry Day - October 17

On Thursday, October 17, the Department of Homeland Security Science and Technology Directorate Silicon Valley Innovation Program, in partnership with CISA, is hosting an Industry Day featuring a panel discussion with experts who have worked on different parts of the software identification puzzle over the past decade, provide descriptive use cases and detailed information about the technical requirements, submission process, and resources available to startups interested in submitting applications to the Software ADG Generation Topic Call.

The event will be held in person in Menlo Park, CA and livestreamed via Zoom.

Blogs

Open Source Security | CISA (19)

Blog: With Open Source Artificial Intelligence, Don’t Forget the Lessons of Open Source Software

CISA highlights its recent work in Open Source Artificial Intelligence.

Open Source Security | CISA (20)

Blog: Continued Progress Towards a Secure Open Source Ecosystem

CISA highlights its work to across the federal government to secure Open Source Software (OSS) since it held its first Summit on OSS Security.

Open Source Security | CISA (21)

Blog: Lessons from XZ Utils: Achieving a More Sustainable Open Source Ecosystem

CISA describes how the agency has responded to the XZ Utils compromise and how every technology manufacturer can take a Secure by Design approach to securing open source software.

Open Source Security | CISA (22)

Blog: Memory Safe and Secure Coding

Director Jen Easterly stresses the importance of safe and responsible coding.

Open Source Security | CISA (23)

Blog: Open Source Software Must Start with Secure Code

CISA calls upon developers to make open source software secure from the start.

Watch Our CISA Live! on Open Source Software Security

On March 7, CISA held a CISA Live! on LinkedIn Live on open source software security. CISA’s Aeva Black,Open Source Security Section Chief, and Jack Cable, Senior Technical Advisor, discussed how CISA is collaborating with the open source community, federal partners, and the private sector to foster a more secure and resilient OSS ecosystem. This event offered participants an opportunity to learn about how CISA is working to strengthen the security of open source ecosystems, including package managers, along with ensuring the secure use of OSS within the federal government.

Contact Us

Do you have feedback on our Open Source Security work, or ideas where we can help contribute? Please share your thoughts by emailing us at: [email protected].

Open Source Security | CISA (2024)
Top Articles
Cruel & Unusual Punishment | Criminal Attorney in Los Angeles, CA
How to Delete All Content and Settings on the Nintendo Switch
Sound Of Freedom Showtimes Near Governor's Crossing Stadium 14
Plaza Nails Clifton
Wmu Course Offerings
Free VIN Decoder Online | Decode any VIN
Aces Fmc Charting
Encore Atlanta Cheer Competition
Ncaaf Reference
Savage X Fenty Wiki
Es.cvs.com/Otchs/Devoted
Palace Pizza Joplin
David Turner Evangelist Net Worth
Beau John Maloney Houston Tx
Webcentral Cuny
Wicked Local Plymouth Police Log 2022
Glenda Mitchell Law Firm: Law Firm Profile
Ge-Tracker Bond
Decosmo Industrial Auctions
Team C Lakewood
The BEST Soft and Chewy Sugar Cookie Recipe
Masterkyngmash
How many days until 12 December - Calendarr
Betaalbaar naar The Big Apple: 9 x tips voor New York City
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
Evil Dead Rise Ending Explained
49S Results Coral
60 Second Burger Run Unblocked
UPS Drop Off Location Finder
Jr Miss Naturist Pageant
Dreammarriage.com Login
What Time Is First Light Tomorrow Morning
Reading Craigslist Pa
9 oplossingen voor het laptoptouchpad dat niet werkt in Windows - TWCB (NL)
Puretalkusa.com/Amac
Courtney Roberson Rob Dyrdek
Winta Zesu Net Worth
Booknet.com Contract Marriage 2
Samsung 9C8
Page 5747 – Christianity Today
Laura Houston Wbap
Great Clips Virginia Center Commons
Craigslist Com Brooklyn
99 Fishing Guide
sin city jili
Zom 100 Mbti
Best brow shaping and sculpting specialists near me in Toronto | Fresha
Lagrone Funeral Chapel & Crematory Obituaries
Arre St Wv Srj
Wayward Carbuncle Location
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5694

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.