Summary
Feedback incorporated from the 78 public comments CISA received in response to our Request for insecure or outdated cryptographic functions, hardcoded credentials, and product support actions to prevent SQL injection vulnerabilities. Updates actions to prevent command injection (MFA) specific to operational technology support phishing-resistant MFA. As outlined in the Cybersecurity and Infrastructure Security Agency’s (CISA’s) Secure by Design initiative, software manufacturers should ensure that security is a core consideration from the onset of software development and throughout the entirety of the development lifecycle. This voluntary guidance provides an overview of product security bad practices that are considered exceptionally risky, particularly for software manufacturers who produce software used in service of critical infrastructure or national critical functions (NCFs). This guidance also provides recommendations for software manufacturers to mitigate these risks. CISA and the Federal Bureau of Investigation (FBI)—hereafter referred to as the authoring organizations—developed this guidance to urge software manufacturers to reduce customer risk by prioritizing security throughout the product lifecycle.