Loading...
Skip to main content

像很多网站一样,BSA的网站使用cookies来确保网站的高效运作,为我们的用户提供最佳的体验。 您可以在我们的Cookies声明中了解我们使用Cookies的更多信息,以及如何更改浏览器的Cookies设置。 继续使用本网站但不更改您的Cookies设置,即表示您同意我们使用Cookies。

X

JUN 28, 2023 | US

BSA Urges CISA to Use Common Self-Attestation Form for Software to Satisfy ‘Safe Harbor’ Liability Protection

Inside Cybersecurity, June 28, 2023

By Sara Friedman

BSA | The Software Alliance advocates for the federal government to use the self-attestation form for secure software development from CISA and the OMB as an acceptable way to satisfy the national cyber strategy’s proposal for establishing liability protections and a “safe harbor” in its comments.

“It makes sense that a software producer that is certified under FedRAMP would be exempt from submitting an attestation form, as the SSDF practices and tasks reflected in the attestation form reference the security controls in NIST SP 800-53, a central element of FedRAMP. However, the attestation requirements do not necessarily always perfectly align with FedRAMP requirements,” according to BSA.

BSA argues that CISA should clarify that the certification from a 3PAO would meet the attestation form requirement even when a software producer’s FedRAMP certification doesn’t “perfectly align with the requirements of attestation.”

Read More >>

Original Posting: https://insidecybersecurity.com/share/14802

关于 BSA

BSA |“软件联盟”(www.bsa.org) 是全球软件行业的主要倡导者,旨在代表该行业,向政府和国际市场发声。其成员包括全球最具创新力的公司,这些公司制定的软件解决方案,不但能够刺激经济,还能提升现代生活的品质。

BSA 的总部位于华盛顿特区,其营运机构遍布 30 多个国家。BSA 凭借这些机构,率先涉足合规项目,以期促进使用合法软件、倡导制定公共政策,并以此培养技术创新能力,以及推动发展数字经济。

媒体联系人

Michael O’Brien

For Media Inquiries

媒体联系人

Media Inquiries

媒体联系人

Media Inquiries

CONTACTO DE PRENSA

Media Inquiries