{
  "id": 19467,
  "title": "Open Source Code Just as Secure as Proprietary Software—If You Manage It Right, Says CISA",
  "url": "https://urgent.news/2026/07/31/open-source-code-just-as-secure-as-proprietary-software-if-you-manage",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-07-31T21:18:29.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/open-source-code-just-as-secure-as-proprietary-software-if-you-manage-it-right-says-cisa/"
  },
  "original_language": "en",
  "account": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a guide titled \"Open Source Software: Security Principles and Practices,\" which asserts that open source software can be as secure as proprietary software, provided agencies manage it correctly. The guide was published in response to recent cyber exploits, such as Log4Shell and XZ utils, and aligns with two Presidential Executive Orders (14144 and 14306) urging government agencies to enhance software security.\n\nCISA acknowledges the advantages of open source software, including cost-effectiveness and the ability to customize it to meet specific agency requirements. However, it emphasizes that open source software requires a different management approach compared to proprietary software. Malicious hackers and AI agents exploit vulnerabilities in open source software to gain entry and exploit systems. Consequently, agencies must take a more proactive role in patching open source software and understanding the dependencies that accompany it.\n\nTo ensure proper management of open source software, CISA provides established principles for patching and a framework for evaluating the trustworthiness and risk tolerance of software packages. The guide also offers best practices for procuring, deploying, and maintaining open source software.\n\nIn practical terms, agencies looking to utilize open source software should establish a process that supports staff in selecting software that meets the agency's needs while minimizing risks. For instance, an agency's Office of the Chief Information Officer (CIO) might set up a system to pre-approve certain software libraries for use within the agency. Automated tools could assist in verifying safe software packages, and reviews would consider potential risk exposure. Higher-risk components, such as operating systems, could still be individually signed off by the CIO.\n\nTo aid agencies in assessing the trustworthiness of software packages, CISA has developed the C4 Framework, which examines four key factors: Codebase, Community, Conduct, and Configuration. The Codebase factor assesses the source code and dependencies of the software component, their update history, the number of vulnerabilities found, and the out-of-date dependencies relied upon. The Community factor examines the robustness of the community maintaining and contributing to the project, its affiliation with a foundation or a private company, and the project's management. The Conduct factor evaluates the project's management, including the presence of a vulnerability disclosure process and adherence to a code of conduct by the project leaders. The Configuration factor determines whether the default configuration is secure and if there are guides for use in highly-sensitive environments.\n\nCISA recommends that open source AI systems undergo additional scrutiny, emphasizing the importance of transparency and access to the training data, software, and potential vulnerabilities for agencies to analyze and remediate any identified risks or vulnerabilities. CISA has tailored this guide for U.S. federal agencies, although its advice is applicable to businesses in various sectors, such as finance and healthcare, that regularly adopt government guidance.",
  "summary": "Open source can be just as safe as proprietary software, though government agencies (and private enterprises) should take additional measures to secure it properly, according to a new guide published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The report, “Open Source Software: Security Principles and Practices,” provides with guidance to help agencies comply […]",
  "key_points": [
    "Open source software can be as secure as proprietary software with proper management, per CISA.",
    "Recent cyber exploits like Log4Shell and XZ utils highlight need for open source security."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}