CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

CISA lays out new guidance for using open-source software

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3717

As cited

Copy frozen at (site build).

government policy

CISA lays out new guidance for using open-source software

The US Cybersecurity and Infrastructure Security Agency (CISA) published the Open Source Software: Security Principles and Practices guide to help federal agencies manage open source software security, contribute to open source projects, and evaluate open source artificial intelligence systems. The guidance emphasizes that open source software allows independent code review, reducing vendor dependency and security risks. The recommendations address procurement, evaluation, and participation strategies for federal agencies.

Why it matters: Federal agencies must implement these practices to manage open source software risks; practitioners at government organizations need to align procurement and development practices with CISA guidance to reduce supply chain exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary