Securing Open Source Software Act of 2023
This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security.
Open source software means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution.
Specifically, CISA must
CISA must (1) publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community.
The bill requires CISA to assess open source software components used by federal agencies based on the framework and provides for a pilot assessment of critical infrastructure.
CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.
The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software.
Introduced in Senate
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.
Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.
Llama 3.2 · runs locally in your browser
Ask anything about this bill. The AI reads the full text to answer.
Enter to send · Shift+Enter for new line