Site icon TheCyberThrone

NIST Software Security Guidance

Advertisements

NIST spells out security measures for “critical software” used by federal agencies and minimum standards for testing its source code. The best practices could be a model for the private sector as well. Aftermath SolarWinds this has been released.

NIST worked with the CISA, NSA, and gathered input via workshop, which included 1,000 participants from industry, academia and government.

Security Measures for Critical Software

“Recent incidents have demonstrated the need to better protect the … critical software that federal agencies use on-premises, in the cloud, and elsewhere to achieve their mission,” NIST says.

“There must be constant monitoring for anomalous or malicious activity. Preventing breaches is still a ‘must,’ but it is also important to have robust incident detection, response, and recovery capabilities to minimize disruption to agency missions.”

The NIST guidance for Critical Software:

Standards for Software Testing

The software must be designed, built, delivered and maintained in accordance with best practices. Frequent and thorough testing by developers as early as possible in the software development life cycle is one critical practice.

Forcing Action

The administration is attempting to force the individual agencies, which have historically had a wide latitude to handle their own security and IT infrastructure, to adopt foundational best practices.

Adhering to these best practices is going to result in a new and unbudgeted procurement for the agencies. This is often where government security initiatives fail, either the procurement process takes too long or the funds simply aren’t available.

Exit mobile version