1 November 2022

NSA, CISA issue guidance for securing supply chains


NSA, CISA issue guidance for securing supply chains

The US National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and Office of the Director of National Intelligence (ODNI) have released a joint guidance for software suppliers providing a new set of cybersecurity practices to help organizations secure their supply chains.

“The software supplier (vendor) is responsible for liaising between the customer and software developer. Accordingly, vendor responsibilities include ensuring the integrity and security of software via contractual agreements, software releases and updates, notifications, and mitigations of vulnerabilities,” the guide notes.

The agencies also released best practices for developers to help them achieve security through industry and government-evaluated recommendations.

Earlier this week, CISA published a guide with recommendations on how to prevent or reduce the impact of distributed denial of service (DDOS) attacks.

Back to the list

Latest Posts

BreachForums resurrected mere weeks after US-led takedown

BreachForums resurrected mere weeks after US-led takedown

The site reopened for registration, using a new dark web domain while reclaiming its original clearnet domain.
29 May 2024
Google Search document leak reveals inner workings of ranking algorithm

Google Search document leak reveals inner workings of ranking algorithm

The leak contains over 2,500 pages of internal API documentation.
29 May 2024
New North Korean APT focused on espionage and revenue generation, linked to FakePenny ransomware

New North Korean APT focused on espionage and revenue generation, linked to FakePenny ransomware

The group employs traditional and novel attack methods in their operations.
29 May 2024