logo

Will CISA's Secure by Design pledge be a catalyst for better software security?

ID: 24162302-98ac-5328-842f-92a9f5aba626

STIX ID: report--24162302-98ac-5328-842f-92a9f5aba626

Feed Name: ReversingLabs Blog

Date Published: 2024-05-21

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

CISA used the RSA Conference to secure commitments from 68 major software vendors to its Secure by Design pledge, aiming within a year to expand MFA, reduce default passwords, cut common vulnerability classes, increase patch adoption, publish safe VDPs, issue timely CVEs with accurate CWE/CPE data, and improve customers’ ability to detect intrusions. Experts are split on impact—some praising the awareness and commitment-bias benefits, others calling it PR—while highlighting persistent challenges from legacy, vulnerability-centric AppSec practices and noting that if voluntary measures underperform, shifts in incentives or liability may be considered.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.