Resilient Cyber • 119 implied HN points • 01 May 23
- The Federal government is focusing on secure software development, requiring software suppliers to prove they follow certain security practices. This means companies must show they are making software safely before selling it to federal agencies.
- Software developers must also consider how they use open-source software, as they need to show they manage risks associated with those components. This makes them responsible for any issues that might arise from using other people's code.
- Additionally, there is a process where companies can report if they can't meet all the secure practices. This allows them to explain any gaps in compliance and outline their plans to fix them later.