CISA Releases New Guidance on Secure Use of Open Source Software
en.Wedoany.com Reported - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released the guide "Open Source Software: Security Principles and Practices" to assist federal agencies in managing open source software security, participating in open source projects, and evaluating open source artificial intelligence systems.

The guide notes that open source software source code can be independently reviewed, reducing reliance on vendor claims and lowering the risk of being locked into a single vendor; waiving licensing fees and sharing development efforts can reduce costs, and publicly releasing publicly funded software where appropriate can enhance transparency.
CISA recommends that agencies treat open source software as ordinary software assets, assess security before adoption, and monitor throughout the entire lifecycle. Agencies should prioritize projects with active maintenance, understand license terms, and maintain an inventory of open source components in use.
The guide recommends tracking software dependencies, monitoring newly disclosed vulnerabilities, and periodically assessing whether projects remain trustworthy. Software Bills of Materials (SBOMs) help identify affected components when vulnerabilities are disclosed. Agencies should apply security patches as quickly as possible; when custom software or open source projects have no updates available, they should be prepared to contribute fixes. If a project reaches end-of-support or security issues remain unresolved, it should be replaced with a supported alternative. Tools, including artificial intelligence, are increasing the number of vulnerabilities discovered and accelerating patch development; CISA encourages automating dependency management, patch deployment, and security testing wherever possible.
CISA encourages agencies to contribute improvements to the open source projects they use, including security fixes, bug reports, documentation, and technical discussions, and to share changes with the community to reduce duplication of effort, improve software, and publicly disclose government-funded outcomes. Before contributing, agencies should confirm that the project license permits participation and review source code, documentation, and configuration files to prevent exposure of passwords, encryption keys, internal system details, and other confidential information.
For agencies developing their own software, CISA encourages considering open source release from the outset, unless legal, security, or operational reasons preclude it. Internal software inventories should indicate whether a project is intended for public release, sharing within the federal government, or retention. Before release, agencies should check for sensitive information, follow secure development practices, select an appropriate license, and publish documentation, contribution guidelines, vulnerability disclosure policies, and SBOMs alongside the public code repository. After release, agencies must continue to publish updates, address security issues, and clarify when software support ends. If software is custom-developed by contractors, the government should retain the rights to reuse, modify, and, under appropriate conditions, open source the code.
CISA emphasizes that evaluating so-called "open source" artificial intelligence systems must be distinguished from open source software: AI models can be released under open source licenses without disclosing training data. Without access to training data and training processes, organizations may find it difficult to determine model provenance or assess whether development processes or components have been manipulated. Before deployment, agencies should confirm sufficient visibility into development methods, including training data and training processes; when such information is unavailable, the system should be treated as proprietary software of incomplete provenance and subject to stricter risk management.
Related Products

Industrial and Commercial Point-Type Gas Detector
Jinan Benan Technology Development Co., Ltd.


Automatic Aiming Laser Remote Obstacle Removal Robot
Pinggao Group Weihai High-Voltage Apparatus Co., Ltd.

MUX Series Communication Interface Device for Security and Stability Control System
Nanjing NR Electric Co., Ltd.



20 Inch 1600*900 Full HD 60Hz TFT LED Monitor with VGA and DP Interfaces for Desktop Computers-Business Use
Guangzhou Zanying Optoelectronics Technology Co., Ltd.

Comprehensive Mining Automation Control System
Beijing Tianma Intelligent Control Technology Co., Ltd.








