Open source can be just as safe as proprietary software, though government agencies (and private enterprises) should take additional measures to secure it properly, according to a new guide published by the U.S. Cybersecurity and Infrastructure Security Agency ( CISA ). The report, “ Open Source Software: Security Principles and Practices ,” provides with guidance to help agencies comply with two Presidential Executive Orders ( 14144 and 14306 ) which both urged them to do a more thorough job securing the software they use, a response to recent exploits like Log4Shell and XZ utils. CISA acknowledges that open source can provide immeasurable benefits to government agencies, not merely because it is available without licensing fees, but also because agencies can extend the software to meet their own requirements. But at the same time, open source software must be managed differently than proprietary software. Malicious hackers (and increasingly AI agents) use vulnerabilities to gain ...
Latest News and Technology updates