[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTFq9PKuZymssVAmNAFgpNb6eLdL7STi5tqhWWo__M70":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"29bf922f-705c-41bc-90c4-60418e5417f3","Open Source Software: Security Principles and Practices","open-source-software-security-principles-and-practices-443818","Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. Visit CISA’s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email opensource@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. Please share your thoughts! We welcome your feedback. CISA Product Survey","CISA has released new guidance titled 'Open Source Software: Security Principles and Practices' to help federal agencies securely utilize, assess, and publish open source software (OSS). The guidance covers the entire lifecycle of OSS risk management, introduces the C4 Framework for trust assessment, and offers recommendations for vulnerability management, SBOM usage, secure development, and the handling of open source AI systems.","CISA releases guidance on secure use, evaluation, and publishing of open source software.","PUBLICATION Open Source Software: Security Principles and Practices Publish DateJuly 30, 2026 Open Source Software: Security Principles and Practices Related topics: Cybersecurity Best Practices Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems. Visit CISA’s Open Source Security webpage for more resources. CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email opensource@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. Please share your thoughts! We welcome your feedback. CISA Product Survey Tags Audience: Federal Government Language: English Topics: Cybersecurity Best Practices Related Resources Jul 28, 2026 External CI Fortify – Advice for isolating vital systems State and Local Cybersecurity Grant Program (SLCGP) & Tribal Cybersecurity Grant Program (TCGP): Cybersecurity Plan Overview Jul 29, 2026 Publication 2026 Minimum Elements for a Software Bill of Materials (SBOM) Jun 26, 2026 External Russian Intelligence Services Continue to Target Commercial Messaging Applications","https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fresources\u002Fopen-source-software-security-principles-and-practices",null,"2026-07-30T12:00:00+00:00","2026-07-30T16:00:27.407204+00:00",7,[18,21,24],{"name":19,"type":20},"CISA","vendor",{"name":22,"type":23},"Open Source Software","technology",{"name":25,"type":23},"Artificial Intelligence","ade75414-7914-4e23-a450-48b64546ee70",{"id":26,"icon":13,"name":28,"slug":29},"Open Source","open-source",[31,36,38],{"category":32},{"id":33,"icon":13,"name":34,"slug":35},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":37},{"id":26,"icon":13,"name":28,"slug":29},{"category":39},{"id":40,"icon":13,"name":41,"slug":42},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]