everything possible | Shutterstock

Share:

FedScoop – CISA says the form is intended to ensure that “the software producers who partner with the federal government leverage minimum secure development techniques and toolsets.”

Developers whose software is used by the federal government will now need to affirm that they use secure development practices. The form includes a checklist that includes maintaining trusted relationships for authorization and access, using multi-factor authentication, encrypting credentials and other sensitive data, automated checks for vulnerabilities, and maintaining trusted supply chains for source code.

Sources:

Share: