MAR 09, 2022 | US
In Letter to White House, BSA Outlines Recommendations for Open Source Software Security
WASHINGTON – March 9, 2022 – BSA | The Software Alliance today sent a letter to the White House’s National Cyber Director and the Deputy National Security Advisor for Cyber and Emerging Technology outlining 12 recommendations to improve open source software security. These suggestions for the public and private sectors focus on minimizing vulnerabilities in open source software, improving the process of identifying vulnerabilities and developing patches, and expediting the distribution and implementation of patches.
“The log4j vulnerability highlighted the unique challenges of securing open source software. While it’s not realistic to expect any software to be entirely free of vulnerabilities, developers and consumers of open source software can take steps to minimize vulnerabilities and their impact while supporting proactive cybersecurity risk management,” said Henry Young, Director, Policy at BSA | The Software Alliance. “Our recommendations are aggressive but achievable, and we urge the US Government to implement our proposals while working with governments around the world to do the same.”
BSA’s letter includes the following recommendations for making significant improvements in open source software security:
- Developers of open source software should use best practices for developing and assessing software security, such as NIST’s Secure Software Development Framework or the BSA Framework for Secure Software.
- Developers and consumers of open source software should invest in the development and maintenance of open source software they use.
- The US Government should require all colleges and universities that receive federal funds and provide instruction on software development to include appropriate instruction on secure software development processes, secure capabilities, and secure lifecycle management in their curriculum.
- Developers of open source software that have employees should require their employees responsible for developing software to obtain appropriate training on secure development processes, secure capabilities, and secure lifecycle management.
- Developers of open source software should participate in public-private partnership projects that are aimed at implementing and demonstrating secure software development practices.
- Developers of open source software should use best practices for identifying vulnerabilities, coordinating disclosure, and developing patches.
- Developers and consumers of open source software should commit to working together to identify and prioritize the security of the most critical open source software components and the most critical open source software platforms.
- Developers and consumers of open source software should proactively maintain their products and services and have vulnerability identification and management processes that may include periodic automated scans of their software for vulnerabilities contained in up-to-date lists of the most critical software vulnerabilities.
- The US Government, working through the General Services Administration (GSA), should ensure that GSA’s code.gov builds off and is complimentary to the other actions suggested here.
- Developers and consumers of open source software should use best practices for distributing and implementing patches.
- Developers and consumers of open source software should respond to a vulnerability commensurate with the risk it creates.
- Developers of open source software should have a process for considering whether to push out an available patch outside their normal patching schedules.
To read BSA’s full letter, click here.
BSA | The Software Alliance (www.bsa.org) is the leading advocate for the global software industry before governments and in the international marketplace. Its members are among the world’s most innovative companies, creating software solutions that help businesses of all sizes in every part of the economy to modernize and grow.
With headquarters in Washington, DC, and operations in more than 30 countries, BSA pioneers compliance programs that promote legal software use and advocates for public policies that foster technology innovation and drive growth in the digital economy.