CISA and partners issue secure-by-design principles for software manufacturers
Summary
The cybersecurity guidance is the first of its kind, and is intended to speed up cultural shifts within the technology industry that are needed to achieve a safe and secure future online. In particular, the new guidance states that a secure configuration should be “the default baseline, in which products automatically enable the most important security controls needed to protect enterprises from malicious cyber actors.” The three U.S. agencies have published the document jointly with cybersecurity authorities from Australia, Canada, United Kingdom, Germany, Netherlands, and New Zealand. That new strategy calls for critical infrastructure owners and operators to meet minimum security standards and will potentially expose software companies to liability for flaws in their products. As software now powers the critical systems and services we collectively rely upon every day, consumers must demand that manufacturers prioritize product safety above all else.” It asks technology creators to build organizational structures that provide executive level commitment for software manufacturers to prioritize security as a key element of product development. “Insecure technology products can pose risks to individual users and our national security,” said NSA Cybersecurity Director Rob Joyce in a statement.