CISA Publishes Security Guidance on Open-Source Software and AI Models for Federal Agencies
The Cybersecurity and Infrastructure Security Agency published a guidebook Thursday outlining security principles for federal agencies managing open-source software across its full lifecycle. The new framework provides recommendations on patching protocols and evaluating risks associated with open-source artificial intelligence models.
The guidance fulfills a mandate from an executive order originally signed by Joe Biden and later amended by Donald Trump, which directed CISA to issue security recommendations for the federal government. The agency noted the release follows a recent series of attacks targeting open-source software.
From the sources (2 posts)
@cisagovWe’ve released Open Source Software: Security Principles and Practices new guidance to help agencies & organizations securely use & manage open source software across the full lifecycle. Learn more 👉 https://
@cyberscoopnewsThe Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models. An execu