Securing Open Source Software Act of 2022
A BILL
To establish the duties of the Director of the Cybersecurity and Infrastructure Security Agency regarding open source software security, and for other purposes.
Sec. 2 Findings
Sec. 3 Open source software security duties
“(5) Open source software—The term open source software means software for which the human-readable source code is made available to the public for use, study, re-use, modification, enhancement, and re-distribution.
“(6) Open source software community—The term open source software community means the community of individuals, foundations, nonprofit organizations, corporations, and other entities that—
“(A) develop, contribute to, maintain, and publish open source software; or
“(B) otherwise work to ensure the security of the open source software ecosystem.
“(7) Open source software component—The term open source software component means an individual repository of open source software that is made available to the public.”
“(14) support, including by offering services, the secure usage and deployment of software, including open source software, in the software development lifecycle at Federal agencies in accordance with section 2220E; and”
“2220E. Open source software security duties
“(a) Definition—In this section, the term software bill of materials has the meaning given the term in the Minimum Elements for a Software Bill of Materials published by the Department of Commerce, or any superseding definition published by the Agency.
“(b) Employment—The Director shall, to the greatest extent practicable, employ individuals in the Agency who—
“(1) have expertise and experience participating in the open source software community; and
“(2) perform the duties described in subsection (c).
“(c) Duties of the Director
“(1) In general—The Director shall—
“(A) perform outreach and engagement to bolster the security of open source software;
“(B) support Federal efforts to strengthen the security of open source software;
“(C) coordinate, as appropriate, with non-Federal entities on efforts to ensure the long-term security of open source software;
“(D) serve as a public point of contact regarding the security of open source software for non-Federal entities, including State, local, Tribal, and territorial partners, the private sector, international partners, open source software organizations, and open source software developers; and
“(E) support Federal and non-Federal supply chain security efforts by encouraging efforts to bolster open source software security, such as—
“(i) assisting in coordinated vulnerability disclosures in open source software components pursuant to section 2209(n); and
“(ii) supporting the activities of the Federal Acquisition Security Council.
“(2) Assessment of critical open source software components
“(A) Framework—Not later than 1 year after the date of enactment of this section, the Director shall publicly publish a framework, incorporating government, including those published by the National Institute of Standards and Technology, industry, and open source software community frameworks and best practices, including those published by the National Institute of Standards and Technology, for assessing the risk of open source software components, including direct and indirect open source software dependencies, which shall incorporate, at a minimum—
“(i) the security properties of code in a given open source software component, such as whether the code is written in a memory-safe programming language;
“(ii) the security practices of development, build, and release processes of a given open source software component, such as the use of multi-factor authentication by maintainers and cryptographic signing of releases;
“(iii) the number and severity of publicly known, unpatched vulnerabilities in a given open source software component;
“(iv) the breadth of deployment of a given open source software component;
“(v) the level of risk associated with where a given open source software component is integrated or deployed, such as whether the component operates on a network boundary or in a privileged location; and
“(vi) the health of the community for a given open source software component, including, where applicable, the level of current and historical investment and maintenance in the open source software component, such as the number and activity of individual maintainers.
“(B) Updating framework—Not less frequently than annually after the date on which the framework is published under subparagraph (A), the Director shall—
“(i) determine whether additional updates are needed to the framework described in subparagraph (A); and
“(ii) if the Director determines that additional updates are needed under clause (i), make those updates to the framework.
“(C) Developing framework—In developing the framework described in subparagraph (A), the Director shall consult with—
“(i) appropriate Federal agencies, including the National Institute of Standards and Technology;
“(ii) individuals and nonprofit organizations from the open source software community; and
“(iii) private companies from the open source software community.
“(D) Federal open source software assessment—Not later than 1 year after the publication of the framework described in subparagraph (A), and not less frequently than every 2 years thereafter, the Director shall, to the greatest extent practicable and using the framework described in subparagraph (A)—
“(i) perform an assessment of open source software components used directly or indirectly by Federal agencies based on readily available, and, to the greatest extent practicable, machine readable, information, such as—
“(I) software bills of material that are made available to the Agency or are otherwise accessible via the internet;
“(II) software inventories collected from the Continuous Diagnostics and Mitigation program of the Agency; and
“(III) other publicly available information regarding open source software components; and
“(ii) develop 1 or more ranked lists of components described in clause (i) based on the assessment, such as ranked by the criticality, level of risk, or usage of the components, or a combination thereof.
“(E) Automation—The Director shall, to the greatest extent practicable, automate the assessment conducted under subparagraph (D).
“(F) Publication—The Director shall publicly publish and maintain any tools developed to conduct the assessment described in subparagraph (D) as open source software.
“(G) Sharing
“(i) Results—The Director shall facilitate the sharing of the results of the assessment described in subparagraph (D) with appropriate Federal and non-Federal entities working to support the security of open source software, including by offering means for appropriate Federal and non-Federal entities to download the assessment in an automated manner.
“(ii) Datasets—The Director may publicly publish, as appropriate, any datasets or versions of the datasets developed or consolidated as a result of the assessment described in subparagraph (D).
“(H) Critical infrastructure assessment study and pilot
“(i) Study—Not later than 2 years after the publication of the framework described in subparagraph (A), the Director shall conduct a study regarding the feasibility of the Director conducting the assessment described in subparagraph (D) for critical infrastructure entities.
“(ii) Pilot—If the Director determines that the assessment described in clause (i) is feasible, the Director may conduct a pilot assessment on a voluntary basis with 1 or more critical infrastructure sectors, in coordination with the Sector Risk Management Agency and the sector coordinating council of each participating sector.
“(iii) Reports
“(I) Study—Not later than 180 days after the date on which the Director completes the study conducted under clause (i), the Director shall submit to the appropriate congressional committees a report that—
“(aa) summarizes the study; and
“(bb) states whether the Director plans to proceed with the pilot described in clause (ii).
“(II) Pilot—If the Director proceeds with the pilot described in clause (ii), not later than 1 year after the date on which the Director begins the pilot, the Director shall submit to the appropriate congressional committees a report that includes—
“(aa) a summary of the results of the pilot; and
“(bb) a recommendation as to whether the pilot should be continued.
“(3) Coordination with National Cyber Director—The Director shall—
“(A) brief the National Cyber Director on the activities described in this subsection; and
“(B) coordinate activities with the National Cyber Director, as appropriate.
“(4) Reports
“(A) In general—Not later than 1 year after the date of enactment of this section, and every 2 years thereafter, the Director shall submit to the appropriate congressional committees a report that includes—
“(i) a summary of the work on open source software security performed by the Director during the period covered by the report, including a list of the Federal and non-Federal entities with which the Director interfaced;
“(ii) the framework developed under paragraph (2)(A);
“(iii) a summary of changes made to the framework developed under paragraph (2)(A) since the last report submitted under this subparagraph;
“(iv) a summary of the assessment conducted pursuant to paragraph (2)(D);
“(v) a summary of changes made to the assessment conducted pursuant to paragraph (2)(D) since the last report submitted under this subparagraph, including overall security trends; and
“(vi) a summary of the types of entities with which the assessment was shared pursuant to paragraph (2)(G), including a list of the Federal and non-Federal entities with which the assessment was shared.
“(B) Public report—Not later than 30 days after the date on which the Director submits a report required under subparagraph (A), the Director shall make a version of the report publicly available on the website of the Agency.”
Sec. 4 Software security advisory subcommittee
“(E) Software security, including open source software security.”
Sec. 5 Open source software guidance
“(9) plans and procedures to ensure the secure usage and development of software, including open source software.”