Jump to content

Draft:NIST Secure Software Development Framework

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by 65.246.13.11 (talk) at 14:18, 2 December 2024 (-- Draft creation using the WP:Article wizard --). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

SSDF was developed by NIST based on US Presidential Executive Order 14028 Section 4 (dated May 12, 2021). It provides a framework for securely developing software in the wake of software supply chain attacks and the prevalent use of open source software and third-party libraries. A major concept that was made popular by SSDF was the software bill of materials (SBOM) and the need for documenting the provenance (origin and history) of all software used in a system.

The first version of SSDF (NIST SP 800-218) was published in Feb 2022.

In general, any software that ends up being in a system sold to a federal agency, must have an SSDF self-attestation form submitted by the developer.




References