"As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS," said Chris Butera, acting executive assistant director for cybersecurity.
CISA publishes "Open Source Software: Security Principles and Practices"
The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday titled "Open Source Software: Security Principles and Practices." The document responds to an executive order President Joe Biden signed — and that President Donald Trump later amended — which directed CISA and other agencies to issue open-source security recommendations to federal agencies. CISA presents the guidance as a practical resource to manage the particular tradeoffs of open-source software (OSS), which the agency calls both widely advantageous and uniquely challenging.
Assessing trust, tracking assets, and patching guidance
The guidebook lays out operational steps agencies should take before approving OSS components: evaluate the trustworthiness of an OSS project and track OSS in agency asset management repositories. It offers concrete direction on patching practices, including procedures for when a newly discovered OSS vulnerability lacks an available patch. The document also provides advice on how agencies can contribute to OSS projects, how they might produce OSS themselves, and how to secure rights for government reuse of code when contracting for custom software development.
Open-weight AI models: licenses, transparency, and risk
The guidance singles out AI-related OSS, urging agencies to treat "open source" AI systems differently from other OSS. It states, "Agencies should approach ‘open source’ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software." The guide warns that OSS is increasingly intertwined with emerging technologies such as artificial intelligence and contends that agencies that adapt to OSS's unique characteristics will be better positioned to meet future challenges and leverage new innovations.
Reactions from an open-source security expert
Æva Black, described in the source as an open-source security expert and former OSS lead at CISA, applauded the guidance. She told CyberScoop that the document "demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment." Black highlighted the guidance's recommendations around the risks of deploying unverifiable open-weight AI models on sensitive networks and warned that "Due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis."
Black also accused some proprietary software vendors of attempting to "spread ‘fear, uncertainty, and doubt’ about open source in order to capture public attention, and, I presume, public money," while arguing that "when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure."
What this means for federal civilian agencies, open-source maintainers, and procurement leaders
- Federal civilian agencies: The guidebook asks agencies to formalize evaluation and inventory practices — assessing OSS trustworthiness before approval and tracking components in asset repositories — and to follow the guidance on patching, contribution, and rights for reuse when engaging with OSS and contracted development.
- Open-source maintainers and contributors: The guidance underscores the value of transparency in code and project practices; agencies are being encouraged to rely on their ability to "directly assess code quality and security" in OSS projects rather than depending solely on vendor assurances.
- Procurement leaders and contractors: The document advises securing government reuse rights when contracting for custom software development and provides contractual-oriented recommendations for handling OSS produced or contributed by vendors.
CISA released the OSS guidance alongside several other security documents this week, including collaborative guidance on creating software bills of materials with other agencies and allied governments, recommendations on isolating vital operational technology during crises written with other agencies and allied governments, and updated secure cloud configuration baselines for Google Workspace.
The guidebook frames OSS as neither inherently more nor less risky than other software, but as different in a way that allows agencies to "directly assess code quality and security, rather than relying solely on vendor assurances." The policy directive that prompted the guidance — the executive order signed by President Joe Biden and amended by President Donald Trump — required CISA and partner agencies to issue such recommendations; this publication is the agency's response. The central question the guidance leaves in plain sight is whether federal agencies will adopt the recommended evaluation, inventory, and AI-specific transparency practices quickly enough to keep pace with the "recent slew of attacks on open-source software" the agency cites.




