EO Resource Center
Section 4: Supply Chain
Menu Filters
Section Overview
Section 4 establishes baseline security standards for developing software—especially critical software—that is sold to government, including requiring developers to have greater visibility into their software and making security data publicly available. This section also creates a public-private process to develop new and innovative approaches for secure software development, helps the government use its buying power to ensure software security standards are met, and creates a pilot program where products have labels confirming they were developed securely.
The National Institute of Standards and Technology (NIST) will develop federal guidelines for software security. These guidelines will include standards, procedures, or criteria covering:
- Securing software development environments
- Generating and providing artifacts that demonstrate conformance
- Ensuring code integrity with automation or comparable tools/processes
- Using automation or comparable tools/processes to regularly check for known and potential vulnerabilities and remediate them
- Participating in a vulnerability disclosure program
Executive Order Sections
There is power in strong partnerships.
Learn more about our best-in-class solutions for Executive Order Requirements.
8330 BOONE BLVD, STE 800
Vienna, VA 22182
PH: 703-752-2928
Copyright 2024 Merlin International | Privacy Policy