financetom
Technology
financetom
/
Technology
/
CIS, SAFECode Launch Secure by Design Guide to Help Developers Meet National Software Security Expectations
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
CIS, SAFECode Launch Secure by Design Guide to Help Developers Meet National Software Security Expectations
Oct 23, 2025 6:12 AM

New white paper offers practical, risk-based guidance aligned with NIST SSDF and CIS Controls

EAST GREENBUSH, N.Y., & WAKEFIELD, Mass.--(BUSINESS WIRE)--

The Center for Internet Security, Inc. (CIS®) and the Software Assurance Forum for Excellence in Code (SAFECode) have released a joint white paper, Secure by Design: A Guide to Assessing Software Security Practices, to help software development organizations meet growing national and international expectations for secure software.

The publication addresses a long-standing gap in cybersecurity: the lack of practical, evaluable, and aligned guidance for building software that is secure by design. It offers actionable steps for developers, end users, and government bodies to assess and improve software security practices across six key areas: secure software design, secure development, secure default configuration, supply chain security, code integrity, and vulnerability remediation.

“Secure by Design is more than a slogan; it’s a responsibility,” said Curtis Dukes, Executive Vice President and General Manager of Security Best Practices at CIS. “This guide gives developers and organizations a clear path to implement secure software practices that are both effective and adaptable across different environments.”

The guide builds on NIST’s Secure Software Development Framework (SSDF) and incorporates SAFECode’s Development Groups (DGs) model to tailor recommendations to organizations of varying maturity levels. It also maps practices to the CIS Critical Security Controls® (CIS Controls®) and identifies responsible roles and artifacts to demonstrate compliance. The paper includes a dedicated section on the security implications of artificial intelligence and machine learning (AI/ML), offering insights into emerging risks and considerations.

“By combining the strengths of CIS, SAFECode, and a community of experts, we’ve created a resource that helps developers move from principles to practice,” said Steve Lipner, Executive Director of SAFECode. “This guide supports risk-based decision-making and helps organizations meet the expectations of initiatives like CISA’s Secure by Design and the EU Cyber Resilience Act.”

The guide responds to the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design initiative and supports the mandates related to software security that are outlined in Executive Order 14306, SUSTAINING SELECT EFFORTS TO STRENGTHEN THE NATION’S CYBERSECURITY AND AMENDING EXECUTIVE ORDER 13694 AND EXECUTIVE ORDER 14144, and the relevant portions of Executive Order 14028.

Organizations adopting the practices outlined in the guide may also benefit from existing State safe harbor provisions and compliance frameworks that recognize the use of CIS Controls and NIST SSDF. The guide reinforces the shared responsibility of software developers to deliver secure systems and empowers end users to evaluate software security with confidence.

To arrange an interview with CIS or SAFECode regarding Secure by Design: A Guide to Assessing Software Security Practices, contact [email protected].

About CIS:

The Center for Internet Security, Inc. (CIS®) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit, responsible for the CIS Critical Security Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously refine these standards to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial (SLTT) government entities. To learn more, visit CISecurity.org or follow us on X: @CISecurity.

About SAFECode:

The Software Assurance Forum for Excellence in Code (SAFECode) is a nonprofit organization dedicated to increasing trust in information and communications technology products and services through the advancement of effective software assurance methods. SAFECode brings together leading software companies to share best practices and develop guidance that helps organizations improve the security and integrity of their software. Learn more at safecode.org.

Source: SAFECode

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Expert Outlook: Jabil Through The Eyes Of 5 Analysts
Expert Outlook: Jabil Through The Eyes Of 5 Analysts
Oct 3, 2024
Jabil ( JBL ) underwent analysis by 5 analysts in the last quarter, revealing a spectrum of viewpoints from bullish to bearish. The following table provides a quick overview of their recent ratings, highlighting the changing sentiments over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings 3 2...
A Look Into Autodesk Inc's Price Over Earnings
A Look Into Autodesk Inc's Price Over Earnings
Oct 3, 2024
In the current market session, Autodesk Inc. ( ADSK ) stock price is at $273.12, after a 0.09% drop. However, over the past month, the company's stock increased by 5.16%, and in the past year, by 30.02%. Shareholders might be interested in knowing whether the stock is overvalued, even if the company is not performing up to par in the...
What Analysts Are Saying About Dynatrace Stock
What Analysts Are Saying About Dynatrace Stock
Oct 3, 2024
In the latest quarter, 7 analysts provided ratings for Dynatrace ( DT ) , showcasing a mix of bullish and bearish perspectives. In the table below, you'll find a summary of their recent ratings, revealing the shifting sentiments over the past 30 days and comparing them to the previous months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings 2...
Evaluating Arlo Technologies: Insights From 4 Financial Analysts
Evaluating Arlo Technologies: Insights From 4 Financial Analysts
Oct 3, 2024
Across the recent three months, 4 analysts have shared their insights on Arlo Technologies ( ARLO ) , expressing a variety of opinions spanning from bullish to bearish. The following table encapsulates their recent ratings, offering a glimpse into the evolving sentiments over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish...
Copyright 2023-2026 - www.financetom.com All Rights Reserved