logo

CISA sees elimination of ‘bad practices’ as next secure-by-design step

ID: e4dcf807-8378-5e21-a374-f7edde831fdf

STIX ID: report--e4dcf807-8378-5e21-a374-f7edde831fdf

Feed Name: CyberScoop

Date Published: 2024-10-28

Date Updated: 2026-04-21

Author: mbracken

...
...

CISA announced progress on its secure-by-design initiative with more than 230 vendor commitments and, together with the FBI, published a Product Security Bad Practices guidance to draw attention to risky software-building behaviors—such as default passwords, memory-unsafe languages, SQL/OS command injection via user input, lack of MFA, and poor CVE disclosure—encouraging manufacturers to bake security in by default and prioritize fixes like memory-safe languages; the guidance is posted for public comment until Dec. 2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.