CISA Lays Out New Guidance for Using Open-Source Software
Help Net Security, Monday, August 3rd, 2026
CISA publishes security principles for federal agencies managing open-source software and open AI systems.
The US Cybersecurity and Infrastructure Security Agency released Open Source Software: Security Principles and Practices to help federal agencies manage OSS security, contribute to projects, and evaluate open-source AI systems.
Agencies should assess software security before adoption, maintain component inventories, track dependencies, and apply patches promptly.
The guidance encourages sharing improvements with the wider community and recommends that organizations evaluate open-source AI systems differently from traditional software, since models can be released under open licenses without exposing training data or processes.