CISA Issues International Security-by-Design and Security-by-Default Guidance for Software Manufacturers and Customers

CISA Issues International Security-by-Design and Security-by-Default Guidance for Software Manufacturers and Customers

The Federal Bureau of Investigation, National Security Agency, and cybersecurity authorities in Australia, Canada, United Kingdom, Germany, Netherlands, and New Zealand jointly developed Security-by-Design and Security-by-Default principles for technology manufacturers, which the U.S. Cybersecurity and Infrastructure Security Agency released last week. The advise relies on the White House’s recent launch of the U.S. National Cybersecurity Strategy and encourages a consistent, international approach to software security that emphasises software producers’ obligations across jurisdictions. Enterprise customers are advised to “hold their supplying technology manufacturers accountable for the security outcomes of their products” in the guidance.

Pasted image 0

Caleb Skeath, Partner

A recent post on Covington’s Inside Privacy blog highlights the guidance’s basic principles and future steps for important stakeholders.

Pasted image 0

Ashden Fein, Partner

Pasted image 0

Micaela McMurrough, Partner

For detailed information, as well as the picture copyright, please see the law firm’s original article here: CISA Publishes International Guidance on Implementing Security-by-Design and Security-by-Default Principles for Software Manufacturers and Customers

More news

Trending news

Daniela Lavinia Cudrici argues that law firms in the United Arab Emirates should separate awards from directory rankings when they
Clara-Ann Gordon moves from NKF to Bär & Karrer. She joined the Swiss firm’s partnership on 1 September 2026 and
Young Basile Hanlon & MacFarlane, a Michigan intellectual property boutique, was recognized in Chambers USA 2026 for Intellectual Property, its