Product Security Bad Practices


As outlined in the Cybersecurity and Infrastructure Security Agency’s (CISA’s) Secure by Design initiative, software manufacturers should ensure that security is a core consideration from the onset of software development and throughout the entirety of the development lifecycle.

This voluntary guidance provides an overview of product security bad practices that are considered exceptionally risky, particularly for software manufacturers who produce software used in service of critical infrastructure or national critical functions (NCFs). This guidance also provides recommendations for software manufacturers to mitigate these risks.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • Russian troll farms didn’t sway voters in 2016 election

    January 9, 2023

    A new in-depth study has concluded that the Russian government’s efforts to deploy troll farms on Twitter to sway the 2016 election did not have any measurable impact on the outcome of that race. The U.S. government has been largely united in its assessment that the Kremlin attempted to use online proxies and false internet personas ...

  • Iowa’s largest city cancels classes due to cyber attack

    January 9, 2023

    Iowa’s largest school district cancelled classes for Tuesday after determining there was a cyber attack on its technology network. Des Moines Public Schools announced Monday that classes would be cancelled for its 33,000 students after being “alerted to a cyber security incident on its technology network.” The district said in a news release that it took its ...

  • US Supremes deny Pegasus spyware maker’s immunity claim

    January 9, 2023

    The US Supreme Court has quashed spyware maker NSO Group’s argument that it cannot be held legally responsible for using WhatsApp technology to deploy its Pegasus snoop-ware on users’ phones. Facebook and its WhatsApp subsidiary sued the notorious Isreal-based software company in 2019, alleging that NSO exploited a zero-day bug in WhatsApp to remotely drop Pegasus ...

  • New York Adopts Law Protecting Power Grid from Cyber Attacks

    January 4, 2023

    New York Gov. Kathy Hochul signed legislation to create cybersecurity protections for the state’s energy grid. The legislation (designated A.3904B/S.5579A) will require utilities to prepare for cyberattacks in their annual emergency response plans, just as they would for storm or other hazards. The new protections also give the Public Service Commission enhanced auditing powers to ensure ...

  • Cyber attack leaves six North Carolina counties locked out of their online records

    December 30, 2022

    They’re responsible for keeping and protecting your most important records, but Thursday, a company that works with local governments across North Carolina has been paralyzed by a cyber attack with no end in sight. Cott Systems said they work with 300 local offices in 21 states, but right now that work is on hold and local ...

  • Hackers stole data from multiple electric utilities in recent ransomware attack

    December 27, 2022

    Hackers stole data belonging to multiple electric utilities in an October ransomware attack on a US government contractor that handles critical infrastructure projects across the country, according to a memo describing the hack obtained by CNN. Federal officials have closely monitored the incident for any potential broader impact on the US power sector while private investigators ...