WASHINGTON – Today, global tech trade association 91¿ì»îÁÖ reiterated its call for a standardized and transparent process for software producers to provide self-attestations on secure software development practices. In comments to the Cybersecurity and Infrastructure Security Agency (CISA), 91¿ì»îÁÖ highlights the challenges that government contractors face regarding the roll out process of new information security requirements. CISA developed the draft common form in partnership with the Office of Management and Budget (OMB) to provide federal agencies with a standardized way to implement the requirements that aim to ensure the security of federally used software.

91¿ì»îÁÖ agrees with the policy goal of promoting software producers’ adherence to reasonable and risk-based secure software development practices,” said 91¿ì»îÁÖ Executive Vice President of Policy Gordon Bitko. We applaud the Biden Administration’s commitment to leveraging industry’s subject matter expertise in strengthening the United States’ cybersecurity posture and will continue to provide stakeholder feedback through as many formal channels as possible. Yet, the iterative approach to implementing the minimum security requirements, paired with an ambitious timeline, has posed significant challenges for industry to make risk-based decisions on the appropriate investments to provide the federal government with the desired level of secure software development assurance. We are concerned about how the collection process will be operationalized and about the liability implications that the current level of ambiguity poses. We would welcome discussions with OMB and CISA on how potential, perceived, or asserted attestation inaccuracies will be addressed, and we believe that all affected stakeholders desire fair and reasonable treatment in that regard.”

The adoption of a transparent and standardized rollout process that involves industry stakeholders will equip companies with the certainty to manage risks, keep costs low, and provide the desired level of assurance in the timeliest fashion possible. To ensure that the form reflects the latest stage of an iterative process, 91¿ì»îÁÖ calls on CISA to update the form and its associated instructions to reflect important policy changes. The recommended changes for OMB and CISA include ensuring:

  • Form requirements are to be read as expressly written;

  • The reference table in the form’s instructions is for information purposes only and does not influence, modify, embellish, or otherwise affect the five requirements;

  • Software bills of materials (SBOMs) are not part of the minimum requirements of the form; and

  • Software producers are not attesting to third party developed code.

Following the release of the common form requirements detailed in memoranda M-22-18 and M-23-16, 91¿ì»îÁÖ on the Biden Administration to harmonize requirements across the rule making process, and recently asked for to providers so that the tech sector can help achieve the government’s objective of securing the software development process. OMB for implementing OMB Memorandum M-22-18. Currently, software producers face significant barriers, including inconsistent software security practices across the U.S. government.

Cybersecurity, Public Sector]" tabindex="0">Related [Cybersecurity, Public Sector]