Last week CISA published a request for comments on an upcoming draft Secure Software Development Attestation Form. According to its published release, the form will allow federal departments and agencies to be able to obtain attestation of product security from a software producer before using the software on government systems. It goes on to say that the form will create a standardized process for the federal government and software producers that will create transparency on the security of software development efforts.
If this is in your wheelhouse, check out more details in the CISA release, which includes a link to the public comment form in the Federal Register. The deadline to submit input and comments is Dec 18.
If this is in your wheelhouse, check out more details in the CISA release, which includes a link to the public comment form in the Federal Register. The deadline to submit input and comments is Dec 18.