WASHINGTON – Today, global tech trade association 91¿ì»îÁÖ sent a letter to Shalanda Young, Director of the Office of Management and Budget (OMB), with recommendations to advance the U.S. government’s progress towards secure software development. 91¿ì»îÁÖ called upon OMB to harmonize requirements across the federal government through a standardized rulemaking process.
"The memorandum is an important milestone in securing the software development process,” said 91¿ì»îÁÖ’s Gordon Bitko, Executive Vice President of Policy for Public Sector. “Software producers face significant barriers, including ambiguous terminology, confusing timelines, and the potential for regulatory fragmentation. We are concerned that these requests will be applied differently across the government, even within agencies. This creates ambiguity and may ultimately delay progress towards the government’s important software security goals.”
In the letter , 91¿ì»îÁÖ offered the following recommendations as OMB implements Section 4 pursuant to the May 2022 Executive Order on Improving the Nation’s Cybersecurity:
-
Clarify the mandate to leverage one standardized form for all agencies with the option to request addendums for mission-unique needs;
-
Discourage agencies from requiring artifacts until SBOMs are scalable and consumable;
-
Adjust the implementation timeline to allow for a standardized rollout through the established regulatory process under the Administrative Procedure Act;
-
Consider piloting the collection of attestations and artifacts per M-22-18 prior to mandating them; and
-
Leverage the overlap with existing processes to the greatest extent possible to avoid the introduction of additional complexity.
Read the full letter letter.