WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published Open Source Software: Security Principles and Practices, a new resource for federal agencies with considerations and best practices to use and assess Open Source Software (OSS) solutions, contribute to projects, produce OSS, and evaluate open source artificial intelligence (AI) models. The guidance aligns with Executive Order 14144 that highlights the benefits of OSS for federal agencies, and Executive Order 14306 that directs federal networks to be more secure and better manage their use of OSS. Exploits like log4shell and xz utils underscore the need for agencies to understand the dependencies embedded within their software components.
Across the federal government and in every critical infrastructure sector, OSS is a widely used and critical building block in our software supply chain. Many federal agencies use OSS to improve capacity and efficiency that enables them to better fulfill their mission. With this guide, CISA urges agencies to establish a process to review and approve OSS that supports staff in using solutions that best meet their needs while still managing risks. The guidance includes established principles for patching, a framework to evaluate trustworthiness and risk tolerance, and best practices to engage with OSS securely, responsibly and sustainably.
“As part of our statutory mission, CISA remains laser-focused on enhancing the nation's cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.”
For open source AI systems, the guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes. Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks.
For more information, visit Open Source Security on CISA.gov.
