# cisa

The Cybersecurity and Infrastructure Security Agency (CISA) is a U.S. agency responsible for protecting the nation's critical infrastructure from physical and cyber threats.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CISA decides weekly vulnerability bulletin isn't necessary anymore

DevFeed: [CISA decides weekly vulnerability bulletin isn't necessary anymore](<https://devfeed.tech/articles/cisa-decides-weekly-vulnerability-bulletin-isn-t-necessary-anymore-31539.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/16/cisa-decides-weekly-vulnerability-bulletin-isnt-necessary-anymore/5296968>)

Author: Brandon Vigliarolo

Published: 2026-09-16T20:33:48Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [common-vulnerability-scoring-system](<https://devfeed.tech/tags/common-vulnerability-scoring-system.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

CISA is ending its weekly vulnerability bulletin on September 28, shifting from static CVSS scores to risk-based prioritization.

### Source excerpt

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

## CISA's Logging Reference Architecture for OMB M-26-14: What federal agencies should do next

DevFeed: [CISA's Logging Reference Architecture for OMB M-26-14: What federal agencies should do next](<https://devfeed.tech/articles/cisa-s-logging-reference-architecture-for-omb-m-26-14-what-federal-agencies-should-do-next-30890.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/cisa-logging-omb-m-26-14>)

Author: Woody Walton

Published: 2026-09-16T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [audit](<https://devfeed.tech/tags/audit.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [cybersecurity-open-source-standards-log-management-government](<https://devfeed.tech/tags/cybersecurity-open-source-standards-log-management-government.md>), [government](<https://devfeed.tech/tags/government.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This Elastic blog explains CISA's Logging Reference Architecture for OMB M-26-14 and the actions federal civilian executive branch agencies must take. It highlights planning and maturity deadlines, recommends assessing existing capabilities and documenting gaps, and discusses storage tiers, retrieval, immutability, and audit requirements.

### Source excerpt

Now that CISA has released its Logging Reference Architecture (LRA) for OMB M-26-14, federal agencies tasked to complete their logging plans. In this blog, we walk you through the most important aspects of the LRA guidance.

## CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

DevFeed: [CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare](<https://devfeed.tech/articles/cve-mid-year-2026-check-in-volume-vertical-exploitation-rare-27478.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/01/3528/>)

Author: jgamblin

Published: 2026-07-01T15:47:10Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This mid-year review finds that 35,364 CVEs were published in the first half of 2026, up 49.5% from the same period in 2025, while only 85 had entered CISA's KEV list. The article argues that the main challenge is distinguishing exploitable vulnerabilities from the rapidly growing volume of disclosures.

### Source excerpt

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published in the first half of 2026 (Jan 1 - Jun 30, 2026), the volume, the severity, what is actually being exploited, and who ... Read more

## Going beyond CVEs: Chainguard's one day KEV SLA

DevFeed: [Going beyond CVEs: Chainguard's one day KEV SLA](<https://devfeed.tech/articles/going-beyond-cves-chainguard-s-one-day-kev-sla-13068.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/going-beyond-cves-chainguards-one-day-kev-sla>)

Published: 2026-04-28T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-kevs](<https://devfeed.tech/tags/chainguard-kevs.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [exploited-vulnerabilities](<https://devfeed.tech/tags/exploited-vulnerabilities.md>), [kevs](<https://devfeed.tech/tags/kevs.md>), [known-exploitable-vulnerabilities](<https://devfeed.tech/tags/known-exploitable-vulnerabilities.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces a one-calendar-day SLA for remediating CVEs added to the CISA Known Exploited Vulnerabilities Catalog when they affect Chainguard container images. The article explains the SLA's relationship to exploited-vulnerability prioritization and Chainguard's continuous remediation processes.

### Source excerpt

Chainguard introduces a 1-day KEV SLA, ensuring exploited vulnerabilities are fixed fast--aligned with how security teams prioritize real-world threats.

## Prioritizing What Matters: Bringing CVE Intelligence to Splunk

DevFeed: [Prioritizing What Matters: Bringing CVE Intelligence to Splunk](<https://devfeed.tech/articles/prioritizing-what-matters-bringing-cve-intelligence-to-splunk-27476.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/04/18/prioritizing-what-matters-bringing-cve-intelligence-to-splunk/>)

Author: jgamblin

Published: 2026-04-18T23:50:46Z

Content type: release

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [net](<https://devfeed.tech/tags/net.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

An update to the free, open-source CVE Intelligence TA for Splunk adds EPSS, CISA KEV, and CISA SSVC enrichment to a vulnerability database. Version 2.0 includes a pre-joined Risk Priority lookup, four Dashboard Studio views, and automatic hourly updates without API keys or setup pages.

### Source excerpt

I spend a significant amount of my time thinking about EPSS, CVSS, and the inherent gaps in how we prioritize vulnerabilities. We all know the drill: a 9.8 CRITICAL that remains unexploited shouldn't jump the line ahead of a 7.5 HIGH that is being actively used in the wild. Closing that gap between theoretical severity ... Read more

## One Year Later: Signing CISA's Secure by Design Pledge

DevFeed: [One Year Later: Signing CISA's Secure by Design Pledge](<https://devfeed.tech/articles/one-year-later-signing-cisa-s-secure-by-design-pledge-13194.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/one-year-update-to-signing-cisas-secure-by-design-pledge>)

Published: 2025-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [okta](<https://devfeed.tech/tags/okta.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard reviews its progress one year after signing CISA's Secure by Design pledge, including CVE remediation across its container images, company-wide MFA through Okta SSO, and password-free access with automated SSH key provisioning for Chainguard VMs.

### Source excerpt

Chainguard signed CISA's Secure by Design pledge in 2024. One year later, we look at progress we've made in key areas like CVE remediation and disclosures.

## Cisco Umbrella for Government: DNS Security Integrated With CISA Protective DNS

DevFeed: [Cisco Umbrella for Government: DNS Security Integrated With CISA Protective DNS](<https://devfeed.tech/articles/cisco-umbrella-for-government-dns-security-integrated-with-cisa-protective-dns-20374.md>)

Original publisher: [Read original article](<https://umbrella.cisco.com/blog/cisco-umbrella-for-government-dns-security-integrated-with-cisa-protective-dns>)

Author: Christina Hausman

Published: 2024-08-29T08:00:00Z

Content type: release

Language: en

Sources: [OpenDNS](<https://devfeed.tech/sources/opendns.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-umbrella-for-government](<https://devfeed.tech/tags/cisco-umbrella-for-government.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dns-layer-security](<https://devfeed.tech/tags/dns-layer-security.md>), [dns-security](<https://devfeed.tech/tags/dns-security.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [government-cybersecurity](<https://devfeed.tech/tags/government-cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [products-services](<https://devfeed.tech/tags/products-services.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Cisco Umbrella for Government has achieved FedRAMP Moderate authorization and integrates with CISA Protective DNS. The integration provides DNS-layer protection against malware and phishing and supports on-premises and roaming users across several device platforms.

### Source excerpt

Cisco Umbrella for Government has achieved FedRAMP Moderate authorization*. Eligible customers can now leverage Cisco Umbrella for Government for robust DNS security and to meet the mandate for CISA's Protective DNS with enhanced protection for on-premises and roaming client users. Cisco Umbrella DNS-layer security proactively protects against malware and phishing attacks by blocking access to [...] The post Cisco Umbrella for Government: DNS Security Integrated With CISA Protective DNS appeared first on Cisco Umbrella.

## NVD updates: CVSS v4.0, CISA data, and more

DevFeed: [NVD updates: CVSS v4.0, CISA data, and more](<https://devfeed.tech/articles/nvd-updates-cvss-v4-0-cisa-data-and-more-13192.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nvd-updates-cvss-v4-0-cisa-data-and-more>)

Published: 2024-07-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [NVD](<https://devfeed.tech/topics/nvd.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [cvss-v4-0](<https://devfeed.tech/tags/cvss-v4-0.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [github](<https://devfeed.tech/tags/github.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnrichment](<https://devfeed.tech/tags/vulnrichment.md>)

### AI overview

The article explains recent updates to the National Vulnerability Database, including its integration of CISA's Vulnrichment project and enriched CVSS and CWE data. It describes how more complete vulnerability information can help security scanners and teams prioritize and manage vulnerabilities.

### Source excerpt

Learn about the NVD's recent updates, including CISA Vulnrichment data, CVSS v4.0 integration, and how they impact your vulnerability management workflow.

## Signing CISA's Secure by Design pledge

DevFeed: [Signing CISA's Secure by Design pledge](<https://devfeed.tech/articles/signing-cisa-s-secure-by-design-pledge-13231.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/signing-cisas-secure-by-design-pledge>)

Published: 2024-05-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Auth0](<https://devfeed.tech/topics/auth0.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Chainguard describes signing CISA's Secure by Design pledge and explains how its products and internal systems address the pledge's goals. The article discusses passwordless human login through SSO, MFA requirements, phishing-resistant security keys, and limitations in provider support for OIDC MFA claims.

### Source excerpt

Chainguard proudly signs CISA's Secure by Design pledge. Learn why we support this critical software security initiative.

## Working with government and industry to put open source security tooling into practice

DevFeed: [Working with government and industry to put open source security tooling into practice](<https://devfeed.tech/articles/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice-13342.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice>)

Published: 2023-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [bombshell](<https://devfeed.tech/tags/bombshell.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard describes two open-source SBOM tools developed with the U.S. Department of Homeland Security and other startups: protobom, which translates SBOM data between formats, and bomshell, which combines and composes SBOMs. The initiative aims to improve software supply chain security and visibility.

### Source excerpt

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

## What every CISO should know about the new SSDF security self-attestation form

DevFeed: [What every CISO should know about the new SSDF security self-attestation form](<https://devfeed.tech/articles/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form-13316.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form>)

Published: 2023-08-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [standards](<https://devfeed.tech/tags/standards.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This joint blog post explains a proposed Secure Software Self-Attestation Form published by CISA and its implications for CISOs. It describes how organizations selling software for government use may need to attest to their best efforts to follow NIST's Secure Software Development Framework, while highlighting related software supply chain security practices and regulatory developments.

### Source excerpt

Explore the pivotal SSDF Security Self-Attestation Form, a key resource for CISOs to navigate and enhance security compliance.

## Threat Modeling and Secure by Design

DevFeed: [Threat Modeling and Secure by Design](<https://devfeed.tech/articles/threat-modeling-and-secure-by-design-36728.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cisa-secure-by-design-feedback/>)

Author: Adam

Published: 2023-07-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [complex](<https://devfeed.tech/tags/complex.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>)

### AI overview

The Threat Modeling Manifesto team published feedback to CISA responding to its Secure by Design Guidance. The feedback takes the form of a detailed letter, which was also covered by Infosecurity Magazine.

### Source excerpt

Our feedback to CISA is now public

## Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance

DevFeed: [Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance](<https://devfeed.tech/articles/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance-13241.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance>)

Published: 2023-06-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cicd](<https://devfeed.tech/tags/cicd.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [continuous-verification](<https://devfeed.tech/tags/continuous-verification.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This commentary explains NSA and DHS CISA guidance for securing CI/CD environments. It highlights risks to downstream environments and software consumers, including compromised developer credentials and application libraries, and recommends established software supply chain security frameworks such as SLSA and CNCF best practices.

### Source excerpt

Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

## Government perspectives on software self-attestation requirements

DevFeed: [Government perspectives on software self-attestation requirements](<https://devfeed.tech/articles/government-perspectives-on-software-self-attestation-requirements-13071.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/government-perspectives-on-software-self-attestation-requirements>)

Published: 2023-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

Chainguard CEO Dan Lorenc and CISA Fellow Chris Hughes discuss CISA's draft software self-attestation form, its relationship to federal software supply chain security requirements, and the regulatory context surrounding secure software development.

### Source excerpt

Chainguard CEO Dan Lorenc and Chris Hughes, CISO & Cofounder of Aquia and CISA Fellow discuss the upcoming software self-attestation form.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.