Summary
Software is embedded in countless systems responsible for providing U.S. critical infrastructure services that Americans rely on as well as systems providing national security capabilities. To maintain confidence in national security and critical infrastructure systems, mission owners and operators should be able to trust the system is functional, safe, and secure. The practice of constructing and assessing software-controlled systems to verify their functionality, safety, and security across all conditions (normal, abnormal, and hostile) is referred to as software understanding. Today, mission owners and operators generally lack the adequate capacity for software understanding due, in part, to technology manufacturers building software that greatly outpaces their ability to understand it, creating a software understanding gap. This gap leads to an inability to create software that is secure by design, remediate defects once discovered, maintain software at the speed and scale of mission relevance, and secure software against exploits.