Cybersecurity
NTIA’s cybersecurity multistakeholder processes, conducted in an open and transparent manner, contribute to the security of the nation’s Internet architecture. The consensus-based development of market-based cybersecurity solutions and guidance creates a foundation for increasing digital security. Recent processes include:
- Software component transparency -- creating guidance for the use of a “Software Bill of Materials,” which functions as a list of ingredients that make up software components
- Internet of Things security – addressing key aspects of IoT security, including upgradability and patchability of connected devices
- Cybersecurity vulnerability disclosures – increasing collaboration between security researchers and software and system developers and owners
Related content
Progress on Software Component Transparency
NTIA is hosting its fourth multistakeholder meeting April 11 on software component transparency to work on ways to enable a more secure software ecosystem. We’re excited to report that a great deal of progress has been made since the effort started eight months ago. The goal is to increase transparency around the use of third party software components so that when vulnerabilities are detected, there is a way to quickly remedy problems
The idea is that software developers and organizations can create and share a “software bill of materials” (SBOM) that lists the components that make up software – a concept somewhat similar to food ingredient lists for every product on grocery store shelves.
Since first beginning this work in July 2018, the group has reached broad consensus around the basic value of a software bill of materials. Several working groups are digging into the details of how this would work, and studying what a more secure future can look like if stakeholders widely adopt SBOM across the Internet ecosystem.
Multistakeholder Process on Promoting Software Component Transparency
AGENCY:
National Telecommunications and Information Administration, U.S. Department of Commerce.
ACTION:
Notice of open meeting.
SUMMARY:
The National Telecommunications and Information Administration (NTIA) will convene a meeting of a multistakeholder process on promoting software component transparency on April 11, 2019.
DATES:
The meeting will be held on April 11, 2019, from 10:00 a.m. to 4:00 p.m., Eastern Time.
ADDRESSES: