Skip to main content
HOUSE 3286118th CongressPlaced on the Union Calendar, Calendar No. 127.

Securing Open Source Software Act of 2023

Last Action
7/27/2023

Actions

  • 2023-07-27Placed on the Union Calendar, Calendar No. 127.
  • 2023-07-27Committee on Oversight and Accountability discharged.
  • 2023-07-27Committee on Oversight and Accountability discharged.
  • 2023-07-27Reported (Amended) by the Committee on Homeland Security. H. Rept. 118-160, Part I.
  • 2023-07-27Reported (Amended) by the Committee on Homeland Security. H. Rept. 118-160, Part I.
  • 2023-05-17Ordered to be Reported (Amended) by Voice Vote.
  • 2023-05-17Committee Consideration and Mark-up Session Held.
  • 2023-05-15Referred to the Committee on Homeland Security, and in addition to the Committee on Oversight and Accountability, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
  • 2023-05-15Referred to the Committee on Homeland Security, and in addition to the Committee on Oversight and Accountability, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
  • 2023-05-15Introduced in House
  • 2023-05-15Introduced in House

CRS Summary

As of 2023-07-27 (08)

Securing Open Source Software Act of 2023

This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security.

Open source software means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution.

Specifically, CISA must

  • perform outreach and engagement to bolster the security of open source software;
  • support federal efforts to strengthen open source software security;
  • coordinate with nonfederal entities on efforts to ensure long-term open source software security;
  • serve as a public point of contact regarding open source software security for nonfederal entities; and
  • support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security.

CISA must (1) publish a framework, incorporating government, private sector, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community.

The bill requires CISA to assess open source software components deployed on high value assets at federal agencies based on the framework and provides for a pilot assessment of critical infrastructure.

CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.

Cosponsors (3)

  • Andrew Garbarino (R-NY)
  • Eric Swalwell (D-CA)
  • Nick LaLota (R-NY)

Subjects

  • Computer security and identity theft
  • Computers and information technology
  • Congressional oversight
  • Department of Homeland Security
  • Federal officials
  • Government information and archives
  • Government studies and investigations
  • Performance measurement
Read on Congress.gov

Sourced from Congress.gov (public domain).

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.