CISA, FBI release Secure by Demand guide for software manufacturers to enhance security technology

General News

Summary

Businesses can also help move the needle by making better risk-informed decisions when purchasing software,” Jen Easterly, CISA director, said in a media statement. These questions are informed by the threat landscape observed at CISA and are categorized by sets of actions that, if done correctly by software manufacturers, will drive down exploitable defects and misconfigurations. They include consistently enforcing the use of parameterized queries to prevent SQL injection attacks; adopting web template frameworks with built-in protection against cross-site scripting vulnerabilities; transitioning code to memory-safe languages in a prioritized approach and writing new products in memory-safe languages; and providing secure defaults for developers, such as by providing ‘building blocks’ of secure functions and libraries that make it impossible (or significantly more difficult) to introduce a certain class of vulnerability. In April, CISA announced that it had joined the Minimum Viable Secure Product (MVSP) Working Group. Since launching CISA’s global Secure by Design initiative last year, the agency has received feedback including through its Request for Information that recently closed.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies