Jump to content

Draft:NIST Secure Software Development Framework: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
-- Draft creation using the WP:Article wizard --
(No difference)

Revision as of 14:18, 2 December 2024

SSDF was developed by NIST based on US Presidential Executive Order 14028 Section 4 (dated May 12, 2021). It provides a framework for securely developing software in the wake of software supply chain attacks and the prevalent use of open source software and third-party libraries. A major concept that was made popular by SSDF was the software bill of materials (SBOM) and the need for documenting the provenance (origin and history) of all software used in a system.

The first version of SSDF (NIST SP 800-218) was published in Feb 2022.

In general, any software that ends up being in a system sold to a federal agency, must have an SSDF self-attestation form submitted by the developer.




References