Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 30, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 30, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 30, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 30, 2025

      Does Elden Ring Nightreign have crossplay or cross-platform play?

      May 30, 2025

      Cyberpunk 2077 sequel enters pre-production as Phantom Liberty crosses 10 million copies sold

      May 30, 2025

      EA has canceled yet another game, shuttered its developer, and started more layoffs

      May 30, 2025

      The Witcher 3: Wild Hunt reaches 60 million copies sold as work continues on The Witcher 4

      May 30, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      How Remix is shaking things up

      May 30, 2025
      Recent

      How Remix is shaking things up

      May 30, 2025

      Perficient at Kscope25: Let’s Meet in Texas!

      May 30, 2025

      Salesforce + Informatica: What It Means for Data Cloud and Our Customers

      May 30, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Does Elden Ring Nightreign have crossplay or cross-platform play?

      May 30, 2025
      Recent

      Does Elden Ring Nightreign have crossplay or cross-platform play?

      May 30, 2025

      Cyberpunk 2077 sequel enters pre-production as Phantom Liberty crosses 10 million copies sold

      May 30, 2025

      EA has canceled yet another game, shuttered its developer, and started more layoffs

      May 30, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Tech & Work»CISA unveils new recommendations for developing secure software

    CISA unveils new recommendations for developing secure software

    January 9, 2025

    CISA, the government agency tasked with securing the U.S.’ cyber and physical infrastructure, has released new Information Technology (IT) Sector-Specific Goals (SSGs).

    According to the organization, the IT SSGs complement Cross-Sector Cybersecurity Performance Goals (CPGs) and offer “additional voluntary practices with high-impact security actions.” Organizations can use them to improve the security of their software development practices. 

    The list is broken down into goals for the process of software development and goals for product design. 

    The software development process goals include:

    • Separate all environments used in software development
    • Regularly log, monitor, and review trust relationships used for authorization and access across software development environments
    • Enforce Multi-Factor Authentication (MFA) across software development environments
    • Establish and enforce security requirements for software products used across software development environments
    • Securely store and transmit credentials used in software development environments
    • Implement effective perimeter and internal network monitoring solutions with streamlined, real-time alerting to aid responses to suspected and confirmed cyber incidents
    • Establish a software supply chain risk management program
    • Make a Software Bill of Materials (SBOM) available to customers
    • Inspect source code for vulnerabilities through automated tools or comparable processes and mitigate known vulnerabilities prior to any release of products, versions, or update releases
    • Address identified vulnerabilities prior to product release
    • Publish a vulnerability disclosure policy

    The Product Design goals include:

    • Increase the use of multifactor authentication
    • Reduce default passwords
    • Reduce entire classes of vulnerabilities
    • Provide customers with security patching in a timely manner
    • Ensure customers understand when products are nearing end of life support and security patches will no longer be provided
    • Include Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) fields in every Common Vulnerabilities and Exposures (CVE) record for the organization’s products
    • Increase the ability for customers to gather evidence of cybersecurity intrusions affecting the organization’s products

    Chris Hughes, chief security advisor at Endor Labs and CISA Cyber Innovation Fellow, said: “These are fundamental security practices, reflecting those in other sources such as CISA’s Secure-by-Design Pledge and Secure-by-Design/Default guidance and NIST’s Secure Software Development Framework (SSDF). They’re good reminders and solid cyber hygiene recommendations that most organizations should be doing, especially those in IT and product-centric development environments, with ramifications for downstream customers and consumers.”

    The post CISA unveils new recommendations for developing secure software appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleNew Banshee Stealer Variant Bypasses Antivirus with Apple’s XProtect-Inspired Encryption
    Next Article Code Intelligence launches AI test agent Spark

    Related Posts

    Tech & Work

    Sunshine And March Vibes (2025 Wallpapers Edition)

    May 30, 2025
    Tech & Work

    The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

    May 30, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    8 ways I use Microsoft’s Copilot Vision AI to save time on my phone and PC

    News & Updates

    This viral iPhone keyboard case is the most ingenious accessory I’ve tested

    Development

    How to Build a Scalable URL Shortener with Distributed Caching Using Redis

    Development

    Getting Started with GitHub: Upload, Clone, and Create a README

    Machine Learning
    GetResponse

    Highlights

    Building SaaS Website #05: Total.js View Engine Basics

    February 10, 2025

    Welcome back to our TotalGPT SaaS website development journey! In this post, we’re diving deep…

    Linux Show Player is a cue player designed for stage productions

    April 24, 2025
    Phishing Up 175%: India’s New Cyber Report Flags BFSI Sector Vulnerabilities

    Phishing Up 175%: India’s New Cyber Report Flags BFSI Sector Vulnerabilities

    April 8, 2025

    News Pinterest Predicts Design Trends for 2025

    December 7, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.