[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLRA_MuhoV6o6VwOsLFlbLhw8dNKdbo2Row_YV9xNV_Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"9464b0be-783d-4322-a596-ebc8d4f523f7","cisa-releases-guidance-on-secure-open-source-software-practices","29bf922f-705c-41bc-90c4-60418e5417f3","CISA Releases Guidance on Secure Open Source Software Practices","Federal agencies and organizations broadly rely on open source software without always understanding the inherited risks, unvetted dependencies, and lack of formal support that can accompany it. CISA's new guidance highlights that OSS use without structured risk assessment creates significant supply chain and vulnerability exposure — particularly as open source components are embedded deep within critical systems. The introduction of the C4 Framework and SBOM requirements signals a shift toward treating OSS with the same rigor applied to commercial software. Without visibility into what open source components are running in your environment, organizations cannot effectively patch, respond to, or govern their software risk. This matters because a single compromised or unpatched OSS dependency can cascade across thousands of downstream systems.","**Immediate actions:**\n- Conduct an inventory audit of all open source components currently in use across your organization's systems.\n- Generate or obtain a Software Bill of Materials (SBOM) for every critical application to establish dependency visibility.\n\n**Long-term improvements:**\n- Adopt the CISA C4 Framework to formally assess trust levels before integrating any new open source software.\n- Establish a formal OSS governance policy that defines approval, monitoring, and retirement processes for open source components.\n- Integrate OSS vulnerability scanning into CI\u002FCD pipelines to catch known CVEs before code reaches production.\n\n**Detection measures:**\n- Subscribe to vulnerability feeds (e.g., NVD, OSV) and configure automated alerts for CVEs affecting your tracked OSS dependencies.\n- Implement continuous monitoring of open source AI systems and models for behavioral anomalies or unexpected updates.",[12,13,14,15,16,17,18,19,20],"NIST SP 800-161r1 (Supply Chain Risk Management)","NIST SSDF (SP 800-218) - Secure Software Development Framework","CIS Control 2 - Inventory and Control of Software Assets","CIS Control 7 - Continuous Vulnerability Management","CISA C4 Framework for OSS Trust Assessment","Executive Order 14028 - SBOM Requirements","NIST SP 800-53 SA-12 (Supply Chain Protection)","NIST SP 800-53 RA-5 (Vulnerability Monitoring and Scanning)","GDPR Article 32 (Security of Processing — applicable to OSS handling personal data)","published","2026-07-30T16:22:56.740335+00:00","2026-07-30T16:22:56.619+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fresources\u002Fopen-source-software-security-principles-and-practices","open-source-software-security-principles-and-practices-443818","Open Source Software: Security Principles and Practices",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]