CISA Issues Recommendations on Open-Source Software Security
The Cybersecurity and Infrastructure Security Agency (CISA) published a guidebook for federal agencies to aid them in managing security risks with open-source software, touching on topics like patching and open-source AI models. This guidance comes after an executive order signed by President Joe Biden and amended by President Donald Trump, which ordered CISA and other agencies to issue open-source security recommendations to federal agencies.
According to Chris Butera, acting executive assistant director for cybersecurity, "CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry, and the open-source community to understand and securely use OSS." Butera encouraged federal civilian agencies to review the guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.
Benefits and Tradeoffs of Open-Source Software
The document, "Open Source Software: Security Principles and Practices," highlights the advantages of open-source software, which offers benefits in efficiency, cost, security transparency, and more. However, it also notes that open-source software has unique tradeoffs. As the guidance reads, "All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances."
Guidance on Evaluating and Securing Open-Source Software
The guidance emphasizes the importance of evaluating the trustworthiness of an OSS project before approving an OSS component for use. It also details how agencies should track OSS in their asset management repositories and deal with patching, including when there’s a new OSS vulnerability that doesn’t have a patch. Additionally, it offers advice on how agencies might contribute to OSS projects, produce them, and secure rights for government reuse of code when contracting for custom software development.
The guidance also explains how agencies should approach open-weight AI models, which require a different approach due to the lack of transparency in open-source licenses for AI software. As the guidance states, "Agencies should approach ‘open source’ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software."
Expert Reaction and Importance of Responsible Open-Source Software Use
Æva Black, an open-source security expert and former OSS lead at CISA, applauded the agency for the guidance, stating that it "demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open source during a crucial moment." Black singled out the recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks, emphasizing the importance of responsible open-source software use.
Black also noted that due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis. However, she believes that when used responsibly and maintained collaboratively, open-source software is, and will remain, the safest and most cost-effective means for building large-scale public infrastructure.
Recent CISA Guidance and Updates
CISA has produced a range of security guidance and updated advisory materials, including guidance on the creation of software bills of materials, the isolation of vital operational technology during a crisis, and the release of updated secure cloud configuration baselines for Google Workspace.
Source: CyberScoop