Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Federal Civilian

CISA Releases Open Source Software Security Guidance for Agencies

by Miles Jamison
July 31, 2026
in Federal Civilian, News
CISA seal. CISA has released guidance to help federal agencies securely use open source software.

The Cybersecurity and Infrastructure Security Agency has released guidance to help federal agencies securely use open source software.

  • CISA’s new guidance outlines practices for agencies to adopt, assess and contribute to open source software securely
  • The resource addresses risks tied to software dependencies, including vulnerabilities exposed by incidents such as Log4Shell
  • Agencies are encouraged to establish review and approval processes before deploying open source tools

The Cybersecurity and Infrastructure Security Agency has released new guidance to help federal agencies securely use, assess and contribute to open source software.

Table of Contents

    • You might also like
    • Former HHS ASPR CIO Dennis Papula Joins Labor Department as Deputy CIO
    • Army Needs More Training on AI During ‘Messy’ Period, G-2 CAIO Says
    • NASA Seeks States to Host US Space Academy
  • What Is the CISA Open Source Software Resource?
  • What Does the CISA Guide Recommend?

You might also like

Former HHS ASPR CIO Dennis Papula Joins Labor Department as Deputy CIO

Army Needs More Training on AI During ‘Messy’ Period, G-2 CAIO Says

NASA Seeks States to Host US Space Academy

What Is the CISA Open Source Software Resource?

CISA said Thursday the Open Source Software: Security Principles and Practices resource provides federal agencies with considerations and best practices for adopting and vetting open source tools, participating in OSS projects, developing open source products and evaluating open source AI models.

The agency said OSS is widely used throughout the federal government and critical infrastructure sectors as a key part of the software supply chain, helping agencies support mission needs while managing software-related risks. The guidance addresses the need for agencies to understand dependencies within software components, citing vulnerabilities such as Log4Shell and xz utils as examples of OSS-related risks.

CISA Releases Open Source Software Security Guidance for Agencies

CISA’s guidance highlights the growing need for agencies to strengthen cybersecurity practices as they adopt emerging technologies and manage software risks. Hear from DHS leaders and industry experts on evolving cyber priorities at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10. Book your seat today.

What Does the CISA Guide Recommend?

The CISA guide recommends that agencies have a formal review and approval process in place before adopting open source tools, so that security risks are managed from the outset. The resource lays out patching principles, a software trustworthiness and risk assessment method, and practices for secure, responsible and sustainable OSS project engagement.

Two executive orders inform the guidance: Executive Order 14144, which points to the advantages OSS offers federal agencies, and Executive Order 14306, which calls on federal networks to tighten security and manage OSS use more effectively. The guidance follows earlier cybersecurity policy changes under EO 14144, which established requirements for secure software development practices and CISA oversight responsibilities.

CISA advises that agencies should not classify an AI system as open source for risk-management purposes unless they can first verify transparency into its key components, including its training data. The agency noted that this kind of transparency and access lets organizations analyze software components, identify vulnerabilities and mitigate security risks.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

DOE Names Andrew McClure to Lead CESER Amid Push to Fortify Energy Infrastructure

Next Post

NRO Successfully Launches NROL-95 Mission Through National Security Space Launch Program

Recommended For You

National Archives and Records Administration Seeks Chief Data Officer

by Jane Edwards
October 14, 2021
National Archives and Records Administration Seeks Chief Data Officer

The National Archives and Records Administration (NARA) has begun its search for a chief data officer that will advise NARA’s chief information officer, deputy CIO, chief technology officer...

Read moreDetails

CGI Federal’s Horace Blackman Named Rector With George Mason University

by William McCormick
June 14, 2024
CGI Federal’s Horace Blackman Named Rector With George Mason University

Horace Blackman, senior vice president with CGI Federal and head of its Defense, Intelligence and Space Business Unit, has been named Rector of the Board of Visitors (BOV)...

Read moreDetails

Lisa Costa: DevOps Implementation Shows ‘Cultural Shift’ in Software Dev’t

by Brenda Marie Rivers
November 13, 2019
Lisa Costa: DevOps Implementation Shows 'Cultural Shift' in Software Dev't

Lisa Costa, chief information officer of the U.S. Special Operations Command, said at a Red Hat event that DevOps methodology has helped reduce turnaround times for software development...

Read moreDetails

Hughes Invests $50M in Consortium to Acquire OneWeb; Pradman Kaul Quoted

by Sarah Sybert
June 17, 2024
Pradman Kaul

Hughes Network Systems will participate in the winning consortium that will acquire OneWeb, the Low Earth Orbit (LEO) satellite operator, out of bankruptcy by investing $50 million in...

Read moreDetails

DIU Offers Opportunities for GSA Industry Partners to Develop Tech Platforms for National Security Applications

by Jane Edwards
August 24, 2024
Contracting_272x270

The General Services Administration has released a document informing GSA industry partners that they can participate in the Defense Innovation Unit’s competitive Commercial Solutions Opening process and contribute...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!