How CISA’s secure software development attestation form falls short
ID: aa9a9fec-6130-51ec-a22e-1548f4d4fa35
STIX ID: report--aa9a9fec-6130-51ec-a22e-1548f4d4fa35
Feed Name: ReversingLabs Blog
CISA and the White House OMB released the Secure Software Development Attestation Form, requiring federal software suppliers (including continuously updated SaaS) to attest—via CEO or authorized designee—to NIST SSDF-aligned practices such as secure development environments, MFA, monitoring, encryption, vulnerability management, and disclosure programs. Experts warn that “wiggle words” (e.g., “to the greatest extent feasible,” “good-faith effort”) and the omission of explicit SBOM and comprehensive supply-chain controls leave gaps against modern supply-chain attacks (e.g., tampering, malware injection, signature manipulation, leaked secrets). Agencies must collect attestations within three months for critical software and six months for other covered software (by June 8 and Sept 8, 2024).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
