Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Civilian

CISA Releases Open Source Software Security Guidance for Agencies

by Miles Jamison
July 31, 2026
in Civilian, News
CISA seal. CISA has released guidance to help federal agencies securely use open source software.

The Cybersecurity and Infrastructure Security Agency has released guidance to help federal agencies securely use open source software.

  • CISA’s new guidance outlines practices for agencies to adopt, assess and contribute to open source software securely
  • The resource addresses risks tied to software dependencies, including vulnerabilities exposed by incidents such as Log4Shell
  • Agencies are encouraged to establish review and approval processes before deploying open source tools

The Cybersecurity and Infrastructure Security Agency has released new guidance to help federal agencies securely use, assess and contribute to open source software.

Table of Contents

    • You might also like
    • VA OIG Flags Delay, Cost and Security Risks in Benefits Platform Modernization
    • NIST Seeks Input on National Vulnerability Database Modernization
    • DOE Seeks Input for Genesis Mission Initiative to Build Open-Weight AI Models
  • What Is the CISA Open Source Software Resource?
  • What Does the CISA Guide Recommend?

You might also like

VA OIG Flags Delay, Cost and Security Risks in Benefits Platform Modernization

NIST Seeks Input on National Vulnerability Database Modernization

DOE Seeks Input for Genesis Mission Initiative to Build Open-Weight AI Models

What Is the CISA Open Source Software Resource?

CISA said Thursday the Open Source Software: Security Principles and Practices resource provides federal agencies with considerations and best practices for adopting and vetting open source tools, participating in OSS projects, developing open source products and evaluating open source AI models.

The agency said OSS is widely used throughout the federal government and critical infrastructure sectors as a key part of the software supply chain, helping agencies support mission needs while managing software-related risks. The guidance addresses the need for agencies to understand dependencies within software components, citing vulnerabilities such as Log4Shell and xz utils as examples of OSS-related risks.

CISA Releases Open Source Software Security Guidance for Agencies

CISA’s guidance highlights the growing need for agencies to strengthen cybersecurity practices as they adopt emerging technologies and manage software risks. Hear from DHS leaders and industry experts on evolving cyber priorities at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10. Book your seat today.

What Does the CISA Guide Recommend?

The CISA guide recommends that agencies have a formal review and approval process in place before adopting open source tools, so that security risks are managed from the outset. The resource lays out patching principles, a software trustworthiness and risk assessment method, and practices for secure, responsible and sustainable OSS project engagement.

Two executive orders inform the guidance: Executive Order 14144, which points to the advantages OSS offers federal agencies, and Executive Order 14306, which calls on federal networks to tighten security and manage OSS use more effectively. The guidance follows earlier cybersecurity policy changes under EO 14144, which established requirements for secure software development practices and CISA oversight responsibilities.

CISA advises that agencies should not classify an AI system as open source for risk-management purposes unless they can first verify transparency into its key components, including its training data. The agency noted that this kind of transparency and access lets organizations analyze software components, identify vulnerabilities and mitigate security risks.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

DOE Names Andrew McClure to Lead CESER Amid Push to Fortify Energy Infrastructure

Next Post

NRO Successfully Launches NROL-95 Mission Through National Security Space Launch Program

Recommended For You

Maynard Holliday: DOD Should Take Ownership of AI Technical Baseline

by Jane Edwards
June 10, 2024
Maynard Holliday

Maynard Holliday, deputy chief technology officer for critical technologies at the Department of Defense, said DOD recognizes the “need to own the technical baseline” of artificial intelligence as...

Read moreDetails

CenturyLink Expands On-Demand Network Connectivity to Google Cloud Platform; Paul Savill Quoted

by William McCormick
October 16, 2019
CenturyLink Expands On-Demand Network Connectivity to Google Cloud Platform; Paul Savill Quoted

CenturyLink announced on Wednesday that the company has provided a new option for connecting business premises and public data centers to cloud environments with the expansion of its...

Read moreDetails

Combined Program Office to Improve US Capability Against Advanced Missile Threats; Col. Brian Denaro Quoted

by Jane Edwards
September 19, 2022
Combined Program Office to Improve US Capability Against Advanced Missile Threats; Col. Brian Denaro Quoted

Space Systems Command is overseeing a new combined program office that seeks to enhance U.S. capability to counter, deter and win against threats posed by competitors in space.Established...

Read moreDetails

Linux Foundation Launches OCUDU Ecosystem Foundation

by Jane Edwards
March 2, 2026
6G. The Linux Foundation launched the OCUDU Ecosystem Foundation to drive AI-RAN innovation and support 56 and 6G services.

The Linux Foundation has launched the Open Centralized Unit Distributed Unit, or OCUDU, Ecosystem Foundation to drive open source artificial intelligence-radio access network, or AI-RAN, innovation and accelerate...

Read moreDetails

Jose Arrieta: HHS Needs to Prepare Acquisition Workforce for New Business Strategies

by Brenda Marie Rivers
October 31, 2019
Jose Arrieta: HHS Needs to Prepare Acquisition Workforce for New Business Strategies

Jose Arrieta, chief information officer of the Department of Health and Human Services, has said that the department seeks to modify its acquisition strategy as it seeks to...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!