Bad software cost US businesses $2.41 trillion in 2022

General News

Summary

Indeed, despite the SolarWinds and Log4j incidents serving as wake-up calls for exposure to third-party applications, open source repositories have remained ripe for exploitation over the past year. Early in its lifecycle, an application does not have the full feature set that can be found in later versions,” said Anita DAmico, vice president of cross-portfolio solutions and strategy at Synopsys and a CISQ board member. Significant parts of the software sold in commercial systems are pulled from free repositories or other sources, and few companies put time into documenting the provenance of each line of code. The Biden administration has tasked the the Cybersecurity and Infrastructure Security Agency and the National Institute for Standards and Technology with developing a framework to promote the creation and implementation of SBOMs better manage vulnerabilities like Log4J and SolarWinds that are deeply embedded across industry and other sectors. Just last week, several trade groups, including the U.S. Chamber of Commerce and the Cybersecurity Coalition, published an open letter asking Congress to delay SBOM for defense contractors until the ecosystem matures.

Classifications

industries
No industries detected
applications
Engineering & Scientific

AskAI Classifications

Labels
Electronic Design Automation (EDA) Semiconductor Software Developer Tools

Linked Companies