- CISA published a new guide titled 'Open Source Software: Security Principles and Practices' for federal agencies.
- The guide provides best practices for using, assessing, contributing to, and producing OSS, as well as evaluating open source AI models.
- It aligns with Executive Orders 14144 and 14306, emphasizing the need for secure OSS management following exploits like log4shell and xz utils.
- Agencies are urged to establish a process to review and approve OSS, including principles for patching, trustworthiness evaluation, and secure engagement.