{"id":629591,"date":"2023-04-15T09:49:31","date_gmt":"2023-04-15T14:49:31","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/04\/15\/cisa-pressures-tech-vendors-to-ship-secure-software-out-of-the-box\/"},"modified":"2023-04-15T09:49:31","modified_gmt":"2023-04-15T14:49:31","slug":"cisa-pressures-tech-vendors-to-ship-secure-software-out-of-the-box","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/04\/15\/cisa-pressures-tech-vendors-to-ship-secure-software-out-of-the-box\/","title":{"rendered":"CISA pressures tech vendors to ship secure software \u2018out of the box\u2019"},"content":{"rendered":"<div>\n<section>\n<p><time title=\"2023-04-13T20:22:06+00:00\" datetime=\"2023-04-13T20:22:06+00:00\">April 13, 2023 1:22 PM<\/time>\n\t\t\t<\/p>\n<\/section>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"377\" src=\"https:\/\/venturebeat.com\/wp-content\/uploads\/2022\/02\/GettyImages-1076658494.jpg?fit=750%2C377&#038;strip=all\" alt=\"Programmer \/ coder \/ data privacy \/ password \/ secrets\"><\/p>\n<div>\n<p><span>Programmer looking at code on a screen<\/span><\/p>\n<p><em>Image Credit: Przemyslaw Klos \/ EyeEm via Getty<\/em><\/p>\n<\/div><\/div>\n<\/p><\/div>\n<div id=\"primary\" role=\"main\">\n<article id=\"post-2869416\">\n<div>\n<div id=\"boilerplate_2682874\">\n<p><em>Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success<\/em>. <em><a href=\"https:\/\/avolio.swapcard.com\/Transform2023\/registrations\/Start?utm_source=vb&#038;utm_medium=boiler&#038;utm_content=landingpage&#038;utm_campaign=T23_BoilerPlates\">Learn More<\/a><\/em><\/p>\n<hr>\n<\/div>\n<p>Today, the Cybersecurity and Infrastructure Security Agency (<a href=\"https:\/\/www.cisa.gov.co\/\" target=\"_blank\" rel=\"noreferrer noopener\">CISA<\/a>), the Federal Bureau of Investigation, the National Security Agency (<a href=\"https:\/\/www.nsa.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">NSA<\/a>) and cybersecurity authorities across Australia, Canada, United Kingdom, Germany, Netherlands and New Zealand released new <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/us-and-international-partners-publish-secure-design-and-default-principles-and-approaches\" target=\"_blank\" rel=\"noreferrer noopener\">guidance<\/a> urging software manufacturers to take the steps necessary to ship products that are secure-by-design, \u201cout of the box.\u201d\u00a0<\/p>\n<p>The guidance, a report named \u201cShifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default,\u201d aims to \u201cencourage every technology manufacturer to build their products in a way that prevents customers from having to constantly perform monitoring, routine updates, and damage control on their systems.\u201d\u00a0<\/p>\n<p><strong>>>Don\u2019t miss our newest special issue: <a href=\"https:\/\/venturebeat.com\/venturebeat-special-issue-the-quest-for-nirvana-applying-ai-at-scale\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><a href=\"https:\/\/venturebeat.com\/venturebeat-special-issue--data-centers-in-2023-how-to-do-more-with-less\" target=\"_blank\" rel=\"noreferrer noopener\">Data centers in 2023: How to do more with less<\/a>.<<<\/strong><\/p>\n<p>It also outlines the steps organizations can take to implement secure-by-design and secure-by-default approaches, which are essential for minimizing vulnerabilities and bugs before their release to the market, ensuring software remains resilient to exploitation from threat actors.\u00a0\u00a0<\/p>\n<p><html><body><\/p>\n<div id=\"boilerplate_2803147\">\n<h3>Event<\/h3>\n<div>\n<p><span>Transform 2023<\/span><\/p>\n<div id=\"gm0a52976\">\n<p>Join us in San Francisco on July 11-12, where top executives will share how they have integrated and optimized AI investments for success and avoided common pitfalls.<\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/avolio.swapcard.com\/Transform2023\/registrations\/Start?utm_source=vb&#038;utm_medium=incontent&#038;utm_content=landingpage&#038;utm_campaign=T23_incontent\"><br \/>\n                Register Now            <\/a>\n                        <\/p>\n<\/div>\n<p><\/body><\/p>\n<p>\u201cBuilding security into the design process is not only good practice, it\u2019s also very effective in mitigating flaws in software before they reach the consumer. The challenge, however, is for organizations to adopt these practices without affecting the business, as this process takes time and requires resources that can impact the bottom line,\u201d said Ray Kelly, fellow at <a href=\"https:\/\/www.synopsys.com\/software-integrity.html\" target=\"_blank\" rel=\"noreferrer noopener\">Synopsys Software Integrity Group<\/a>.<\/p>\n<p>The report comes less than a year after the EU introduced the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act\" target=\"_blank\" rel=\"noreferrer noopener\">Cyber Resilience Act<\/a>, which set out to codify a cybersecurity framework for hardware and software producers to improve the security of products during the design and development phase.\u00a0<\/p>\n<p>Both the Cyber Resilience Act and CISA\u2019s new guidance highlights there is an industry-wide shift away from placing the burden of security on end-user organizations and customers toward making software vendors more transparent and accountable for the level of bugs and vulnerabilities present in released products.\u00a0<\/p>\n<p><strong>VentureBeat&#8217;s mission<\/strong> is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. <a href=\"https:\/\/info.venturebeat.com\/website-preference-center.html?utm_source=VBsite&#038;utm_medium=bottomBoilerplate\" data-type=\"URL\" data-id=\"https:\/\/info.venturebeat.com\/website-preference-center.html\">Discover our Briefings.<\/a><\/p>\n<p>\t\t\t\t<\/html><\/div>\n<\/p><\/div>\n<p><a href=\"https:\/\/venturebeat.com\/security\/cisa-pressures-tech-vendors-to-ship-secure-software-out-of-the-box\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Tim Keary<\/p>\n","protected":false},"excerpt":{"rendered":"<p>April 13, 2023 1:22 PM Programmer looking at code on a screenImage Credit: Przemyslaw Klos \/ EyeEm via Getty Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More Today, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation<\/p>\n","protected":false},"author":1,"featured_media":629592,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23654,46,44880],"tags":[],"class_list":{"0":"post-629591","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-pressures","8":"category-technology","9":"category-vendors"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/629591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=629591"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/629591\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/629592"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=629591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=629591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=629591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}