Resilient Cyber • 79 implied HN points • 13 Mar 24
- CISA has released a final form for secure software development that vendors need to follow to sell software to the Federal government. This means companies must prove their software is developed with important security practices.
- The attestation form applies to software developed or significantly changed after September 14, 2022, making it crucial for many vendors. This rule covers popular Software as a Service (SaaS) products as well.
- Not all software is included; for example, software created directly by Federal agencies and open-source software is exempt. This leaves some gaps in security measures that need attention, especially for software that might still pose risks.