US Government ramps up cybersecurity measures with new OMB guidelines
Summary
The US OMB has launched new guidance on the prerequisites and procedures for federal agencies to acquire security guarantees from software vendors. This builds upon President Joe Biden’s cybersecurity executive order from May 2021, with the OMB having issued a directive (M-22-18) last year necessitating software vendors to assure the security of their products. At the very least, vendors must provide a self-attestation form, with the potential for further requirements such as a software bill of materials (SBOM), other artifacts, or running a vulnerability disclosure programme. The most recent memorandum, M-23-16, reiterates the previous directives and extends the deadline for US federal agencies to receive attestations. Furthermore, attestations are required even for software modified, configured, or deployed by a contractor on behalf of an agency.