Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Government Technology

CISA, NIST Post Document on Securing Software Supply Chain

by Christine Thropp
April 27, 2021
in Government Technology, News
CISA, NIST Post Document on Securing Software Supply Chain

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released Defending Against Software Supply Chain Attacks, a document containing information on software supply chain risks and providing guidance on the application of frameworks from NIST for cyber supply chain risk management and secure software development.

Table of Contents

  • You might also like
  • US Leveraging Advanced Technologies in Philippines for Asian Ambitions
  • SSA Seeks Industry Input on Enterprise AI Strategy
  • DHS Builds 2 Systems to Address Biometric Identity Verification Challenges

You might also like

US Leveraging Advanced Technologies in Philippines for Asian Ambitions

SSA Seeks Industry Input on Enterprise AI Strategy

DHS Builds 2 Systems to Address Biometric Identity Verification Challenges

CISA said Monday that its Defending Against Software Supply Chain Attacks publication warns against the consequences of attacks to an organization's software supply chain, including privileged and persistent access to a victim network, and lists measures that can help prevent and mitigate attacks and enhance supply chain resilience.

According to the document, software customers are advised to create and execute a program for managing identified vulnerabilities and to employ resilience measures for limiting the impact of a successful attack against a vulnerable software.

It cited NIST's key practices for applying a cyber supply chain risk management approach, including establishing a C-SCRM program and integrating it across the organization, knowing and managing critical components, collaborating with key suppliers and including them in resilience and improvement efforts, and planning for the full life cycle.

For software vendors, the document recommends preparing for secure software development by defining security requirements, automating developer and security toolchains, creating criteria and processes for data collection for security evaluations. Suppliers are also encouraged to establish SSDF roles and responsibilities within the software development life cycle.

CISA said vendors are encouraged to take a systems security engineering approach to safeguard their development infrastructure and implement NIST's SSDF to protect the cyber supply chain from malicious software content or vulnerabilities.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

FBI, DHS Provide Information on Russian Intell Agency’s Cyber Exploitation Techniques

Next Post

Octo and Sevatec Complete Branding Integration; Mehul Sanghani Quoted

Recommended For You

Cyber Vulnerability Disclosure Bill Clears House

by Nichols Martin
March 23, 2018
Cyber Vulnerability Disclosure Bill Clears House

The House voted Tuesday to pass a bill that would mandate the Department of Homeland Security to provide lawmakers more information on DHS' policies and procedures for disclosing...

Read moreDetails

Edward O’Callaghan Named DOJ Acting Principal Associate Deputy Attorney General

by Nichols Martin
April 4, 2018
Edward O’Callaghan Named DOJ Acting Principal Associate Deputy Attorney General

Edward O’Callaghan Edward O’Callaghan, principal deputy assistant attorney general of the Justice Department's national security division, has been named acting principal associate deputy attorney general at DOJ. He will...

Read moreDetails

Two Senators Urge DoD Secretary to Back 355-Ship Goal

by Jane Edwards
December 6, 2022
Two Senators Urge DoD Secretary to Back 355-Ship Goal

Sens. Susan Collins (R-Maine) and Angus King (I-Maine) have called on Defense Secretary and two-time Wash100 award winner Mark Esper to support the current administration’s plan to increase...

Read moreDetails

Maxar Names Dr. Heather Wilson to Board of Directors; Dan Jablonsky Quoted

by Sarah Sybert
January 19, 2021
Maxar Names Dr. Heather Wilson to Board of Directors; Dan Jablonsky Quoted

Maxar Technologies has appointed Dr. Heather Wilson, two-time Wash100 Award recipient, to the company’s Board of Directors to serve as director for a term expiring at the Maxar’s...

Read moreDetails

Artemis II SLS Mission Flight Software Passes 1st Phase of Qualification Testing

by Jamie Bennet
July 5, 2023
Artemis II SLS Flight Software

NASA software engineers have so far completed 58,000 test cases as part of formal qualification of the flight software to be used on the Artemis II Space Launch...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!