Industry Seeks Consensus on Government’s Secure Software Compliance Process
MAR 24, 2022 | US
Industry Seeks Consensus on Government’s Secure Software Compliance Process
FedScoop, March 24, 2022
By Dave Nyczepir
Government and industry need to reach consensus on a supply chain maturity model allowing tech companies to definitively prove they’re in compliance with the recently mandated federal framework for secure software development, experts say.
Exactly which artifacts — like threat models, log entries, source code files and vulnerability scan reports — and relevant metadata agencies should require companies to present in support of their attestations they meet federal software requirements remains up for debate.
If OMB does intend on requiring audits, it needs to ensure qualified auditors exist — lest companies struggle to bring their software to government, said Henry Young, director of policy at the Business Software Alliance.
“If you’re going to require third-party attestation, there needs to be a third party,” Young said.
Original Posting: https://www.fedscoop.com/industry-consensus-software-compliance-process/
À PROPOS DE BSA
BSA | The Software Alliance (www.bsa.org) est le principal organisme de défense et de promotion de l’industrie du logiciel auprès des administrations gouvernementales et sur le marché international. Ses membres comptent parmi les entreprises les plus innovantes au monde, à l’origine de solutions logicielles qui stimulent l’économie et améliorent la vie moderne.
Basée à Washington, DC et présente dans plus de 30 pays, BSA est pionnière en matière de programmes de conformité qui encouragent l’utilisation légale de logiciels et plaide en faveur de politiques publiques à même de promouvoir l’innovation technologique et de favoriser la croissance économique numérique.