Application Security

CISA, FBI Seek Public Comment on Software Security Bad Practices Guidance

CISA and the FBI are requesting public comment on new guidance regarding risky software security bad practices.

CISA and the FBI are requesting public comment on new guidance regarding risky software security bad practices.

The US cybersecurity agency CISA and the FBI have released new guidance on security bad practices for software manufacturers and are inviting the public to provide feedback on it.

The guidance urges the makers of software and services for the critical infrastructure or national critical functions (NCFs) to prioritize security throughout the development process and reduce customer security risks.

It offers an overview of product security bad practices considered exceptionally risky and provides recommendations for mitigating them, in line with CISA’s Secure by Design initiative.

“The guidance contained in this document is non-binding and while CISA encourages organizations to avoid these bad practices, this document imposes no requirement on them to do so,” the agency notes.

The authoring agencies have divided the product security bad practices into three categories, namely product properties, security features, and organizational processes and policies.

Bad practices related to product properties, or the security-related qualities of software, include the use of memory-unsafe languages, the inclusion of use input in SQL query and operating system command strings, the use of default passwords, and the use of components that contain known vulnerabilities or issues listed in CISA’s KEV catalog.

Advertisement. Scroll to continue reading.

When it comes to security features, bad practices include the lack of multi-factor authentication (MFA) and the lack of capabilities to gather evidence of intrusion in the baseline version of a product.

Organizational processes and policies refer to software makers’ transparent approach to security, and bad practices include the failure to publish CVEs with CWEs in a timely manner and not having a published vulnerability disclosure policy.

“While this guidance is intended for software manufacturers who develop software products and services in support of critical infrastructure, all software manufacturers are strongly encouraged to avoid these product security bad practices,” CISA notes.

The authoring agencies are encouraging interested parties to provide feedback on the guidance by December 2, 2024, via the Federal Register.

Related: CISA Releases Cyber Defense Alignment Plan for Federal Agencies

Related: MFA Isn’t Failing, But It’s Not Succeeding: Why a Trusted Security Tool Still Falls Short

Related: ICS Environments: Insecure by Design

Related: Today’s Network Is Different, Not Dead – Here’s How You Secure It

Related Content

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Government

Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.

ICS/OT

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

Application Security

Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.

ICS/OT

The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.

Risk Management

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version