Nearly 70 of the world's largest software and cybersecurity vendors signed the Cybersecurity and Infrastructure Security Agency (CISA)’s Secure by Design pledge. This initiative, part of a broader effort to integrate security features into software development, has attracted tech giants such as Amazon Web Services (AWS), Cisco, Google, Hewlett Packard Enterprise (HPE), IBM, Microsoft and more than a dozen top-tier cybersecurity firms including Cloudflare, CrowdStrike, Fortinet, and Palo Alto Networks.
At the Secure By Design pledge launch event at RSAC 2024, CISA Director Jen Easterly said this initiative follows the White House's National Cybersecurity Strategy, which calls for shifting the burden of cybersecurity from individuals, small businesses and local governments to more capable entities like the technology manufacturers.
“Everyone here lives the reality of our current threat landscape. The problem set is really daunting but with the folks in this room, the energy, the commitment, I am truly optimistic that together we can make a real impact in the space over the next year,” Easterly said at the event. “And frankly, we have no other choice”
CISA's Secure by Design pledge goals
Participating software manufacturers are pledging to work over the next year to demonstrate measurable progress toward seven goals:
- Multifactor authentication (MFA): Vendors commit to demonstrate actions taken to measurably increase the adoption of MFA in their products within a year.
- Default passwords: They will demonstrate measurable progress toward reducing default passwords across their products.
- Vulnerability reduction: They will take action for a significant measurable reduction in the prevalence of one or more vulnerability classes.
- Security patches: They will demonstrate measures to ensure a measurable increase in the installation of security patches by customers.
- Vulnerability disclosure policy: Participating vendors will publish a vulnerability disclosure policy (VDP) that encourages public vulnerability testing and responsible disclosure.
- Common vulnerabilities and exposures (CVEs): They will improve transparency and timeliness in vulnerability reporting by including accurate Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) fields in every CVE record for their products.
- Evidence of intrusions: They will demonstrate a measurable increase in the capability of customers to gather evidence of cybersecurity intrusions affecting the manufacturer’s products.
Besides the large vendors that signed on the pledge, CISA Senior Technical Advisor Jack Cable recommends every company that is building a software product should take a look at the pledge and consider applying it to their products. “Because as we know attackers are going to do what's easiest and that is exploiting a simple software vulnerability.”
Fortinet details its software security commitment
As one of the first cybersecurity vendors to sign CISA’s Secure by Design pledge, Fortinet claims its product developments and major manufacturing partners' qualifications and selections adhere to various industry standards and frameworks, including National Institute of Standards and Technology (NIST) 800-53 (Security and Privacy Controls for Information Systems and Organizations ) and NIST 800-161 (Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations).
Fortinet also uses tools and techniques such as static and dynamic application security testing, software composition analysis, vulnerability scanning, penetration testing, and manual code audits for security product testing.
Its Fortinet Product Security Incident Response Team is responsible for maintaining security standards for products and proactively and transparently disclosing vulnerabilities.
Comments