Low New document us

CISA publishes guidance on securely using and managing open source software in federal agencies

Original title: Open Source Software: Security Principles and Practices

CISA published a new guidance document for federal agencies on the secure and effective use of open source software (OSS) and open source AI models. The guide provides best practices for reviewing and approving OSS solutions, patching vulnerabilities, evaluating trustworthiness and risk tolerance, and engaging with OSS responsibly. Federal agencies must establish processes to review OSS, obtain transparency into AI system components including training data, and understand software dependencies to identify and remediate vulnerabilities before deployment.

What changed

  • CISA released 'Open Source Software: Security Principles and Practices' guidance document aligned with Executive Order 14144 and Executive Order 14306, providing federal agencies with considerations and best practices for OSS use, assessment, contribution, and production
  • Guidance includes established principles for patching and a framework for evaluating trustworthiness and risk tolerance to support federal agencies in secure OSS adoption
  • Agencies are directed to establish processes to review and approve OSS solutions before deployment to manage risks and ensure solutions meet mission needs
  • For open source AI systems, the guidance requires agencies to obtain sufficient transparency into all relevant components, including training data, to enable risk assessment, vulnerability analysis, and remediation

Who is affected

Federal civilian agencies in the United States. The guidance applies across all federal departments and critical infrastructure sectors that use open source software and AI models.

Language
EN

Frameworks

CISA

Open the original source