So, remember that 2023 National Defense Authorization Bill?
There’s a key provision: vendors can’t sell software to the DoDo that has ANY known CVEs. At least, that’s how some are interpreting it. It’s driving a discussion in the security community, as covered in CyberScoop. Quoting the piece.
The debate boils down to two key arguments: the requirement is unnecessary and impossible to achieve or a game-changing move that will begin holding software vendors accountable for selling faulty technology.
The Biden Administration is on the side of holding software vendors responsible for making sure their goods don’t contain known common vulnerabilities and exposures or CVEs. The software industry should emulate the automotive industry, where “manufacturers retain ownership and responsibility” through the life of the vehicle, said Anne Neuberger, Deputy National Security Advisor for Cyber and Emerging Technology.
“The model in tech for too long has been that it’s the users’ responsibility to patch devices and systems and to recover from an incident when a vulnerability is exploited — and that model needs to change,” Neuberger told CyberScoop in an interview on Friday. “That certainly includes patching critical CVEs before a product is sold and maintaining visibility of new CVEs and responsibility for them.”
In the “something has to change” bucket, the government uses its buying power to enact change. While I worry about new incentives not to report issues to ensure the software can continue to be sold, I’m inclined to favor less tolerance of issues by purchasers. Putting financial incentives around repairing issues changes behavior. Making it a buying criterion at least brings it to light.
