cisaregulatorNewsThe Broadside2 min read

CISA sets IT SSGs for secure software development

CISA can call them voluntary while critical-infrastructure buyers convert the goals into supplier evidence requests.


TL;DR

The Cybersecurity and Infrastructure Security Agency (CISA) released voluntary information technology (IT) Sector Specific Goals (SSGs) on Jan. 7 for secure development, product design and software supply chain risk management. They reach primes, subcontractors, independent software vendors and contractors serving critical infrastructure, with practices covering development-environment separation, trust-relationship monitoring, phishing-resistant multi-factor authentication, secrets management and supply chain risk management. The next 18 months are a procurement story: customer contracts can mandate what CISA frames as voluntary.

The Cybersecurity and Infrastructure Security Agency’s (CISA) new information technology (IT) Sector Specific Goals (SSGs) are voluntary, but they have an obvious procurement path. CISA released the goals Jan. 7 for the IT and product design sector, aligning them to Secure by Design principles and aiming them at secure development, product design, incident response and software supply chain risk management. CISA says the goals are specific to IT while also providing “minimum foundational practices” for software and product developers across critical infrastructure. Minimum practices have a habit of showing up in supplier reviews.

What CISA is asking for

The recommended actions are concrete: separate software development environments with network segmentation and access controls; log, monitor and review trust relationships used for authorization and access; require phishing-resistant multi-factor authentication for development environments; keep credentials and sensitive data out of source code and store them in encrypted systems such as secrets managers; enforce security requirements for software products used in development; and establish a software supply chain risk management program.

That list asks for operational evidence, the kind buyers can request without waiting for a regulator. A prime, subcontractor, independent software vendor or contractor serving a critical-infrastructure customer can expect questions about diagrams, access logs, MFA coverage, secrets handling and supplier risk processes. The next 18 months are a contract-cycle story: security addenda, renewal questionnaires and supplier risk reviews can carry these goals downstream faster than a new directive.

Where the framework pressure comes from

CISA developed the goals with the IT Sector Coordinating Council, which gives procurement teams an answer when suppliers call the bar unrealistic. The agency’s fact sheet also crosswalks IT software-development goals to the NIST Secure Software Development Framework, NIST Cybersecurity Framework 2.0 and CISA’s secure software development attestation, including environment separation mapped to SSDF PO.5.1 and attestation item 1a (https://www.cisa.gov/resources-tools/resources/information-technology-it-sector-specific-goals-ssgs). That matters because customers do not need to invent a rubric. CISA handed them one.

The open question is whether CISA later ties these IT SSGs to directives or existing frameworks more formally. The practical question arrives first. Suppliers should treat the goals as an evidence gap assessment now, especially for development-environment separation, trust-relationship monitoring, phishing-resistant MFA, secrets management and supply chain risk management. If those artifacts do not exist, the next buyer can ask for them before the supplier has a defensible answer.


Published ·Deep Fathom