<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Senate Bill Addresses Open Source Software Protection in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Senate-Bill-Addresses-Open-Source-Software-Protection/m-p/53769#M5955</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Members of the US Senate Homeland Security Committee have introduced a bill that aims to enhance open-source software security. The Securing Open Source Software Act would direct the Cybersecurity and Infrastructure Security Agency (CISA) to develop a framework for assessing open source software risk. It would also direct the Office of Management and Budget to publish guidance to help agencies secure open source software.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.fedscoop.com/open-source-risk-framework-bill/" target="_blank"&gt;https://www.fedscoop.com/open-source-risk-framework-bill/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 18:30:23 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2022-09-27T18:30:23Z</dc:date>
    <item>
      <title>Senate Bill Addresses Open Source Software Protection</title>
      <link>https://community.isc2.org/t5/Industry-News/Senate-Bill-Addresses-Open-Source-Software-Protection/m-p/53769#M5955</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Members of the US Senate Homeland Security Committee have introduced a bill that aims to enhance open-source software security. The Securing Open Source Software Act would direct the Cybersecurity and Infrastructure Security Agency (CISA) to develop a framework for assessing open source software risk. It would also direct the Office of Management and Budget to publish guidance to help agencies secure open source software.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.fedscoop.com/open-source-risk-framework-bill/" target="_blank"&gt;https://www.fedscoop.com/open-source-risk-framework-bill/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 18:30:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Senate-Bill-Addresses-Open-Source-Software-Protection/m-p/53769#M5955</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-09-27T18:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Senate Bill Addresses Open Source Software Protection</title>
      <link>https://community.isc2.org/t5/Industry-News/Senate-Bill-Addresses-Open-Source-Software-Protection/m-p/53778#M5959</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Enhance open-source software security" and&amp;nbsp;&lt;/SPAN&gt;"&lt;SPAN&gt;publish guidance to help agencies secure open source software&lt;/SPAN&gt;" are not the same thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To accomplish the former file vulnerability&amp;nbsp;reports, submit patches, sponsor bug-bounties, etc.&amp;nbsp; The latter is just ordinary vulnerability management, for which a CISA already has &lt;A href="https://www.cisa.gov/binding-operational-directive-22-01" target="_blank" rel="noopener"&gt;a directive&lt;/A&gt;.&amp;nbsp; For those of us in private industry,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;stay up to date on patching and keep tabs on the software's reputation.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 19:47:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Senate-Bill-Addresses-Open-Source-Software-Protection/m-p/53778#M5959</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-09-27T19:47:26Z</dc:date>
    </item>
  </channel>
</rss>

