logo

CISA tool aims to boost security for software onboarding

ID: fd5adcc2-9d6a-56ff-9505-13b72c44b5f3

STIX ID: report--fd5adcc2-9d6a-56ff-9505-13b72c44b5f3

Feed Name: ReversingLabs Blog

Date Published: 2025-09-11

Date Updated: 2026-04-29

Author: John P. Mello Jr.

...
...

**CISA** released a free, interactive web tool based on its Software Acquisition Guide to help organizations embed Secure by Design/Default practices into software procurement, offering structured risk questions, exportable summaries, and baseline supplier requirements; experts praise its ability to shift security left and standardize evaluations (e.g., SBOM/VEX, provenance, disclosure, logging, assurance), while critics argue it is cumbersome, evidence-free, and not machine-readable—highlighting the need for automation, verifiable artifacts, and scalable third-party risk workflows to meet modern software supply chain threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.