CISA issues recommendations to federal agencies on open-source software security
The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.
An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).
βAs part of our statutory mission, CISA remains laser-focused on enhancing the nationβs cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,β said Chris Butera, acting executive assistant director for cybersecurity. βCISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.βΒ
The document, βOpen Source Software: Security Principles and Practices,β touts the advantages of open-source software β which anyone can use, modify and share β as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.
βAll software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,β the guidance reads. βOSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSSβs unique characteristics will position themselves to meet future challenges and leverage new innovations.β
The guidance says that agencies need to take steps to evaluate the trustworthiness of an OSS project before approving an OSS component for use, and track OSS in their asset management repositories. It details how agencies should deal with patching, including when thereβs a new OSS vulnerability that doesnβt have one. It offers advice on how agencies might contribute to OSS projects, produce them and secure rights for government reuse of code when contracting for custom software development. And it explains how it should approach open-weight AI models.
βAgencies should approach βopen sourceβ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software,β the guidance states.
Γva Black, an open-source security expert and former OSS lead at CISA, said she applauded her former agency for the guidance, telling CyberScoop that it βdemonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment.βΒ
She singled out its recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks.
βDue to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis,β she said. βMany proprietary software vendors are using this as an opportunity to spread βfear, uncertainty, and doubtβ about open source in order to capture public attention, and, I presume, public money β but when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure.βΒ
CISA has produced a bevy of security guidance and updated advisory materials this week: on the creation of software bills of materials written in conjunction with other agencies and allied governments that won praise from experts; on the isolation of vital operational technology during a crisis, also written with other agencies and allied governments; and the release of updated secure cloud configuration baselines for Google Workspace.
The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.