Jump to content

Draft:NIST Secure Software Development Framework

From Wikipedia, the free encyclopedia

The Secure Software Development Framework (SSDF) was developed by the National Institute of Standards and Technology (NIST)[1] in response to Section 4 of the U.S. Presidential Executive Order 14028, issued on May 12, 2021[2]. The framework provides guidelines for securely developing software, with a focus on reducing vulnerabilities and enhancing security throughout the software development lifecycle.

History

[edit]

In February 2022, the National Institute of Standards and Technology (NIST) published the first version of the Secure Software Development Framework (SSDF) as NIST Special Publication (SP) 800-218.[3] Under this framework, software provided to U.S. federal agencies must include a self-attestation form from the developer, verifying compliance with SSDF practices.[4]

In June 2023, The Register reported that the U.S. Office of Management and Budget (OMB) extended the deadline for federal agencies to collect attestation certificates from software vendors related to compliance with the NIST's Secure Software Development Framework (SSDF). According to the report, this extension was due to the fact that "the form for reporting on such matters isn't complete." The article further noted that the Cybersecurity and Infrastructure Security Agency (CISA) had published a draft Secure Software Self-Attestation Form in April 2023 and set a deadline for comments on June 26.[5]

References

[edit]
  1. ^ "Secure Software Development Framework (SSDF)". National Institute of Standards and Technology (NIST).
  2. ^ Loehr, Tony (2021-12-13). "Executive Order 14028: NIST SSDF Explained". Cycode. Retrieved 2024-12-07.
  3. ^ "NIST SP 800-218: Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities". National Institute of Standards and Technology (NIST). February 2022.
  4. ^ "Title: Secure Software Development Attestation". U.S. General Services Administration (GSA).
  5. ^ "US government extends software security deadline because vendors aren't ready". The Register. 13 June 2023. Retrieved 12 May 2025.