NSA, CISA call on software developers, suppliers to improve open source software management practices

General News

Summary

The document also builds on the previously released series of recommended practices guides for securing the software supply chain. Additionally, the suggested practices listed herein may be applied across a software supply chain’s acquisition, deployment and operational phases,” the report stated. SBOMs are a critical piece of supply chain risk management,” Jon Boyens, the deputy chief of the Computer Security Division at the National Institute of Standards and Technology, told Federal News Network in an interview in October. “But they’re not a silver bullet, and they require an organization to have a broader and deeper vulnerability management program established in order to really reap the benefits of SBOMs,” he added. CISA also facilitates workstreams led by the National Telecommunications and Information Administration on SBOMs-related topics, including cloud and online applications, on-ramps and adoption, sharing and exchanging and tooling and implementation.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies