Source: www.securityweek.com – Author: Ionut Arghire
The cybersecurity agency CISA and other government agencies are calling to action for the US to take the necessary steps to improve cybersecurity by closing the software understanding gap.
This gap is the result of manufacturers building software that mission owners and operators lack the adequate capacity to verify, meaning that they cannot fully understand the software.
“This gap leads to an inability to create software that is secure by design, remediate defects once discovered, maintain software at the speed and scale of mission relevance, and secure software against exploits,” reads a fresh report (PDF) from CISA, DARPA, OUSD R&E, and NSA.
According to the authoring agencies, the US government needs to take decisive action to close the gap before other countries do, such as China, which has invested heavily in technology over the last decade, enhancing its defensive and offensive capabilities. China requires that all software be reviewed by the state and Russia has demanded access to software details to allow it on its markets.
“By closing the gap before other nations and obtaining a deep, scalable understanding of software-controlled systems, including artificial intelligence (AI)-based systems, the United States will secure an advantage in geopolitics for the foreseeable future and will help harden US critical infrastructure from adversarial state-sponsored activity,” the report reads.
The backbone of US critical infrastructure and national security, software-controlled systems include all software running on endpoints, servers, information and communications technology (ICT) systems, OT components for military, space, manufacturing, energy grid, and transport systems, and AI systems.
“To engender high confidence in national security and critical infrastructure systems, mission owners and operators must be able to routinely pose mission-related questions of these systems and receive thorough answers with the speed and confidence the mission demands,” the authoring agencies argue.
The software understanding gap, rooted in today’s software greatly outstripping the operators’ ability to understand it, results in an inability to build vulnerability-free software, to address defects as soon as they are discovered, maintain the software at speed of mission relevance, and secure it against exploits.
Advertisement. Scroll to continue reading.
“The software understanding gap arises from a decades-long disparity of technical investment in software development capabilities unmatched by similar investments in understanding capabilities. The resulting software understanding gap is already extensive,” the report reads.
The software understanding gap, the authoring agencies note, creates a risk to critical infrastructure and national security systems, as operators may not be able to identify all software behaviors potentially jeopardizing the system and spend significant resources to upgrade and patch deployed software.
To address these risks, the authoring agencies urge manufacturers to enhance their secure-by-design programs by including a trusted third-party attestation process, and encourage customers to procure software that has been through a trusted attestation process.
The authoring agencies call for a coordinated action across the US government to close the gap through policies, improvements in technology procurement, legal requirements, technical solutions, and investment in research, engineering, and support.
Addressing software understanding challenges would help mission owners and operators to better evaluate the use of software before placing it in service, would improve confidence in software, and would also result in economic benefits, the authoring agencies say.
Related: Industry Reactions to Biden’s Cybersecurity Executive Order: Feedback Friday
Related: Biden Executive Order Aims to Shore Up US Cyber Defenses
Related: Head of US Cybersecurity Agency Says She Hopes It Keeps up Election Work Under Trump
Original Post URL: https://www.securityweek.com/us-government-agencies-call-for-closing-the-software-understanding-gap/
Category & Tags: Application Security,Government,CISA,guidance – Application Security,Government,CISA,guidance
Views: 2