CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Closing the Software Understanding Gap ↗ source

January 16, 2025 NSA Guidance
Co-sealed by: CISA, DOE, FBI, NSA

Summary

Software is embedded in countless systems responsible for providing U.S. critical infrastructure services that Americans rely on as well as systems providing national security capabilities. To maintain confidence in national security and critical infrastructure systems, mission owners and operators should be able to trust the system is functional, safe, and secure. The practice of constructing and assessing software-controlled systems to verify their functionality, safety, and security across all conditions (normal, abnormal, and hostile) is referred to as software understanding. Today, mission owners and operators generally lack the adequate capacity for software understanding due, in part, to technology manufacturers building software that greatly outpaces their ability to understand it, creating a software understanding gap. This gap leads to an inability to create software that is secure by design, remediate defects once discovered, maintain software at the speed and scale of mission relevance, and secure software against exploits.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.