CISA publishes OSS security guide for federal agencies
Public Sector Action
Summary
Hide ▲
Show ▼
CISA published Open Source Software: Security Principles and Practices for federal agencies on July 30, 2026, giving them guidance for using, assessing, contributing to, and producing OSS. The resource aligns with Executive Order 14144 and Executive Order 14306 and focuses on dependency review, patching, and trustworthiness. It also addresses open source AI models, requiring agencies to look for transparency in components and training data before treating a system as OSS for risk management. The guidance is meant to improve risk management across the federal software supply chain after incidents such as log4shell and xz utils.
Related Happenings
CISA zero-trust SASE guidance for TIC 3.0
Public Sector Action
H score30
First: 25.06.2026 14:30
Last: 25.06.2026 14:30
Sources 1
About this happening:
CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...
CISA zero-trust SASE guidance for TIC 3.0
Public Sector ActionAbout this happening: CISA published new guidance on June 24 for federal civilian executive branch agencies to replace legacy internet gateways with SASE as part of the move from TIC...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
Executive order NSA CISA NIST and Treasury Department created a voluntary pre-release review framework a classified benchmark federal hardening directives and an AI cybersecurity
Public Sector Action
H score26
First: 03.06.2026 14:00
Last: 03.06.2026 14:00
Sources 1
About this happening:
President Donald Trump signed a June 2 executive order creating a voluntary pre-release cybersecurity review for covered frontier AI models, giving the US government a...
Executive order NSA CISA NIST and Treasury Department created a voluntary pre-release review framework a classified benchmark federal hardening directives and an AI cybersecurity
Public Sector ActionAbout this happening: President Donald Trump signed a June 2 executive order creating a voluntary pre-release cybersecurity review for covered frontier AI models, giving the US government a...
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector Action
H score29
First: 05.05.2026 15:00
Last: 05.05.2026 15:00
Sources 1
About this happening:
CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector ActionAbout this happening: CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
Latest development: 06.05.2026 16:15
CISA launched CI Fortify on Tuesday as a planning framework for critical infrastructure operators in water, energy, transportation and communications to prepare for cyber disruption by disconnecting OT systems from third-party and business networks, maintaining essential services in degraded communications conditions, and recovering compromised systems through backups, component replacement, or a transition to manual operations.
CISA joint guide on agentic AI security
Public Sector Action
H score28
First: 01.05.2026 15:00
Last: 01.05.2026 15:00
Sources 1
About this happening:
CISA, ASD ACSC, and other U.S. and international partners published Careful Adoption of Agentic Artificial Intelligence (AI) Services, a joint guide for organizations...
CISA joint guide on agentic AI security
Public Sector ActionAbout this happening: CISA, ASD ACSC, and other U.S. and international partners published Careful Adoption of Agentic Artificial Intelligence (AI) Services, a joint guide for organizations...
Timeline
-
30.07.2026 15:00 2 articles · 5h ago
CISA publishes OSS security guide for federal agencies
Industry Or Public Sector UpdateCybersecurity and Infrastructure Security Agency (CISA) published Open Source Software: Security Principles and Practices for federal agencies, providing considerations and best practices for using, assessing, contributing to, and producing OSS and for evaluating open source AI models. The guide aligns with Executive Order 14144 and Executive Order 14306, urges agencies to establish review and approval processes, and emphasizes patching, trustworthiness, risk tolerance, and transparency into AI system components and training data.
Show sources
- CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software — www.cisa.gov — 30.07.2026 15:00
- CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software — www.cisa.gov — 30.07.2026 15:00