logo

Is CISA's Secure by Design Pledge Toothless?

ID: 6d4b13c5-3080-554e-b51c-a9b8832274b1

STIX ID: report--6d4b13c5-3080-554e-b51c-a9b8832274b1

Feed Name: Dark Reading

Date Published: 2024-05-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

At RSA 2024, major vendors signed CISA's voluntary 'Secure by Design' pledge committing to seven security objectives—multi-factor authentication, default password elimination, reducing classes of vulnerabilities, timely patching, vulnerability disclosure policies, CVE handling, and evidence of intrusions—to encourage better baseline product security. Industry voices quoted in the article frame the pledge as an economic and cultural lever rather than a regulatory instrument, and Claroty data is used to illustrate why focusing on exploitable assets and default credentials can be more impactful than patching every high-CVSS finding.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.