Urgent.News

What's breaking now, across thousands of outlets.

Tech

Open Source Code Just as Secure as Proprietary Software—If You Manage It Right, Says CISA

Open source can be just as safe as proprietary software, though government agencies (and private enterprises) should take additional measures to secure it properly, according to a new guide published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The report, “Open Source Software: Security Principles and Practices,” provides with guidance to help agencies comply […]

Open Source Code Just as Secure as Proprietary Software—If You Manage It Right, Says CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a guide titled "Open Source Software: Security Principles and Practices," which asserts that open source software can be as secure as proprietary software, provided agencies manage it correctly. The guide was published in response to recent cyber exploits, such as Log4Shell and XZ utils, and aligns with two Presidential Executive Orders (14144 and 14306) urging government agencies to enhance software security.

CISA acknowledges the advantages of open source software, including cost-effectiveness and the ability to customize it to meet specific agency requirements. However, it emphasizes that open source software requires a different management approach compared to proprietary software. Malicious hackers and AI agents exploit vulnerabilities in open source software to gain entry and exploit systems.

Consequently, agencies must take a more proactive role in patching open source software and understanding the dependencies that accompany it.

To ensure proper management of open source software, CISA provides established principles for patching and a framework for evaluating the trustworthiness and risk tolerance of software packages. The guide also offers best practices for procuring, deploying, and maintaining open source software.

In practical terms, agencies looking to utilize open source software should establish a process that supports staff in selecting software that meets the agency's needs while minimizing risks. For instance, an agency's Office of the Chief Information Officer (CIO) might set up a system to pre-approve certain software libraries for use within the agency.

Automated tools could assist in verifying safe software packages, and reviews would consider potential risk exposure. Higher-risk components, such as operating systems, could still be individually signed off by the CIO.

To aid agencies in assessing the trustworthiness of software packages, CISA has developed the C4 Framework, which examines four key factors: Codebase, Community, Conduct, and Configuration. The Codebase factor assesses the source code and dependencies of the software component, their update history, the number of vulnerabilities found, and the out-of-date dependencies relied upon.

The Community factor examines the robustness of the community maintaining and contributing to the project, its affiliation with a foundation or a private company, and the project's management. The Conduct factor evaluates the project's management, including the presence of a vulnerability disclosure process and adherence to a code of conduct by the project leaders.

The Configuration factor determines whether the default configuration is secure and if there are guides for use in highly-sensitive environments.

CISA recommends that open source AI systems undergo additional scrutiny, emphasizing the importance of transparency and access to the training data, software, and potential vulnerabilities for agencies to analyze and remediate any identified risks or vulnerabilities. CISA has tailored this guide for U.S. federal agencies, although its advice is applicable to businesses in various sectors, such as finance and healthcare, that regularly adopt government guidance.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in Tech

More from Friday 31 July →