Product Security Bad Practices


As outlined in the Cybersecurity and Infrastructure Security Agency’s (CISA’s) Secure by Design initiative, software manufacturers should ensure that security is a core consideration from the onset of software development and throughout the entirety of the development lifecycle.

This voluntary guidance provides an overview of product security bad practices that are considered exceptionally risky, particularly for software manufacturers who produce software used in service of critical infrastructure or national critical functions (NCFs). This guidance also provides recommendations for software manufacturers to mitigate these risks.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • FBI to form new cryptocurrency unit

    February 17, 2022

    The FBI is forming a new team dedicated to cryptocurrency, according to the Department of Justice (DOJ). The new team will work closely with the National Cryptocurrency Enforcement Team, the DOJ announced Thursday. Prosecutor Eun Young Choi, who has a background in cyber-related crimes, will serve as the National Cryptocurrency Enforcement Team’s first director. Read more… Source: The Hill  

  • Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology

    February 16, 2022

    From at least January 2020, through February 2022, the Federal Bureau of Investigation (FBI), National Security Agency (NSA), and Cybersecurity and Infrastructure Security Agency (CISA) have observed regular targeting of U.S. cleared defense contractors (CDCs) by Russian state-sponsored cyber actors. The actors have targeted both large and small CDCs and subcontractors with varying levels of ...

  • Maryland Air National Guard conduct first-ever defensive cyber training on base network

    February 16, 2022

    MIDDLE RIVER, MD — Members of the 275th Cyberspace Operations Squadron, Maryland Air National Guard, conducted one of the first-ever enduring defensive cyber training missions in a Title 32 mobilization status on an installation’s network, at Warfield Air National Guard Base, Maryland, Nov. 16-19, 2021. “This training is a very unique opportunity and it is the ...

  • Tripwire for real war? Cyber’s fuzzy rules of engagement

    February 14, 2022

    President Joe Biden couldn’t have been more blunt about the risks of cyberattacks spinning out of control. “If we end up in a war, a real shooting war with a major power, it’s going to be as a consequence of a cyber breach of great consequence,” he told his intelligence brain trust in July. Now tensions ...

  • CIA illegally harvested US citizens’ data, senators assert

    February 11, 2022

    Two US senators have gone public with evidence of what they assert is a previously secret bulk data collection effort by the Central Intelligence Agency (CIA), conducted outside the law and without oversight. Democratic Senators Ron Wyden and Martin Heinrich, of Oregon and New Mexico respectively, on Thursday announced that in April 2021 they sent a ...

  • A sign of ransomware growth: Gangs now arbitrate disputes

    February 9, 2022

    Cyber criminal gangs are getting increasingly adept at hacking and becoming more professional, even setting up an arbitration system to resolve payment disputes among themselves, according to a new report by the United States, Australia and the United Kingdom that paints a bleak picture of ransomware trends. Ransomware gangs, which hack targets and hold their data ...