The Cybersecurity and Infrastructure Security Agency on Thursday released a new guide intended to help federal agencies adopt, assess, and contribute to open-source software while better managing supply chain risk, including from open-source artificial intelligence models.
Titled “Open Source Software: Security Principles and Practices,” the resource outlines considerations for using and producing open-source code, established patching principles, a framework for evaluating project trustworthiness and organizational risk tolerance, and recommended practices for engaging with open-source communities securely, responsibly, and sustainably. CISA said the guidance aligns with Executive Order 14144, which highlights the benefits of OSS for federal agencies, and Executive Order 14306, which directs federal networks to improve security and management of open-source components.
The agency urged departments to formalize processes for reviewing and approving OSS so staff can choose effective tools while maintaining risk controls. The document emphasizes the importance of understanding software dependencies—a lesson reinforced by recent high-profile incidents such as Log4Shell and the xz utils backdoor—so agencies can rapidly identify, patch, or mitigate vulnerabilities that may be embedded deep in their technology stacks.
“As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.”
For open-source AI systems, CISA advises agencies to obtain sufficient transparency into all relevant components—including training data—before classifying a product as OSS for risk management purposes. Greater access, the guidance notes, enables teams to study the software, evaluate it for vulnerabilities, and remediate risks that surface.
Open-source code underpins much of the software used across the federal government and critical infrastructure sectors, where agencies often rely on community-developed tools to expand capacity and efficiency. CISA’s new playbook aims to channel that reliance into more deliberate practices: selecting projects with strong maintenance records, integrating timely patching into operations, participating upstream to improve code quality, and documenting how OSS is evaluated and approved inside each organization.
The resource is available on CISA’s website and is part of the broader federal effort to harden software supply chains by promoting secure development practices, improving visibility into third-party components, and accelerating coordinated vulnerability management.





