国防部软件开发和开源软件(OSS)

VIP文档

ID:69461

大小:0.29 MB

页数:8页

时间:2024-02-13

金币:10

上传者:战必胜
DEPARTMENT
OF
DEFENSE
6000
DEFENSE
PENTAGON
WASHINGTON, D.C. 20301-6000
JAN
2 4
2022
CHIEF
INFORMATION
OFFICER
MEMORANDUM
FOR
SENIOR PENTAGON LEADERSHIP
COMMANDANT OF THE COAST GUARD
COMMANDERS OF THE COMBATANT COMMANDS
DEFENSE AGENCY AND DOD FIELD ACTIVITY DIRECTORS
SUBJECT: Software Development and Open Source Software
Over the last two decades, open source software (OSS) has dramatically impacted how
software
is
designed, developed, deployed, and operated. OSS is software for which the human-
readable source code
is
available for use, study, re-use, modification, enhancement, and re-
distribution by the users
of
such software. There are millions
of
publicly-available OSS
components, libraries, and applications capable of accelerat;ng software modernization activities.
The Department's 2018 Cyber Strategy ( attached) directed the Department to increase the
use
of
secure OSS and to use commercial
off
-the-shelf tools when possible. The Department's
forthcoming Software Modernization Strategy centers on the delivery
of
resilient software
capability at the speed
of
relevance. OSS forms the bedrock
of
the software-defined world and
is
critical in delivering software faster. The Department must clearly articulate how, where, and
when it participates, contributes, and interacts with the broader OSS community.
There are two fundamental concerns for the Department that are specific to OSS. First,
using externally maintained code in critical systems potentially creates a path for adversaries to
introduce malicious code into DoD systems. This concern requires a careful supply chain risk
management (SCRM) approach for OSS, which must meet the same rigorous standards for
SCRM and cyber threat testing as any other product. Second, imprudent sharing
of
code
developed for DoD systems potentially benefits adversaries by disclosing key innovations. This
risk is managed through a Modular, Open-Systems Approach (MOSA), which allows systems to
benefit from OSS while protecting critical, innovative components as separate modules.
Pursuant to Federal Source Code Policy (reference (b)) and Public Law 115-91, Section
875 (reference (c)), Attachment 2 provides detailed guidance on the Department's participation,
contribution, and interaction with the broader OSS community. Additional guidance concerning
OSS is available at https://dodcio.defense.gov/Open-Source-Software-FAQ/. The point
of
contact for this effort is Dan Risacher, daniel.r.risacher.c~
ct
Sherman
Attachments:
As stated
CLEARED
For Open Publication
Department of Defense
OFFICE OF PREPUBLICATION AND SECURITY REVIEW
Jan 26, 2022
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭