Legis Daily

Securing Open Source Software Act of 2022

USA117th CongressS-4913| Senate 
| Updated: 12/19/2022
Gary C. Peters

Gary C. Peters

Democratic Senator

Michigan

Cosponsors (1)
Rob Portman (Republican)

Homeland Security and Governmental Affairs Committee

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Securing Open Source Software Act of 2022 This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. Open source software means software for which the human-readable source code is made available to the public for use, study, re-use, modification, enhancement, and re-distribution. Specifically, CISA must perform outreach and engagement to bolster the security of open source software; support federal efforts to strengthen the security of such software; coordinate with nonfederal entities on efforts to ensure the long-term security of such software; serve as a public point of contact regarding the security of such software for nonfederal entities; and support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security. CISA must (1) publicly publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; and (2) update the framework at least annually. The bill provides for a critical infrastructure assessment study and pilot assessment. CISA's Cybersecurity Advisory Committee may establish a software security subcommittee, including open source software security. The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software.

Bill Text Versions

View Text
2 versions available

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Sep 21, 2022
Introduced in Senate
Sep 21, 2022
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sep 28, 2022
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Dec 19, 2022
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 117-278.
Dec 19, 2022
Placed on Senate Legislative Calendar under General Orders. Calendar No. 677.
  • September 21, 2022
    Introduced in Senate


  • September 21, 2022
    Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


  • September 28, 2022
    Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.


  • December 19, 2022
    Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 117-278.


  • December 19, 2022
    Placed on Senate Legislative Calendar under General Orders. Calendar No. 677.

Government Operations and Politics

Advisory bodiesComputers and information technologyComputer security and identity theftCongressional oversightGovernment information and archivesGovernment studies and investigationsPerformance measurement

Securing Open Source Software Act of 2022

USA117th CongressS-4913| Senate 
| Updated: 12/19/2022
Securing Open Source Software Act of 2022 This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. Open source software means software for which the human-readable source code is made available to the public for use, study, re-use, modification, enhancement, and re-distribution. Specifically, CISA must perform outreach and engagement to bolster the security of open source software; support federal efforts to strengthen the security of such software; coordinate with nonfederal entities on efforts to ensure the long-term security of such software; serve as a public point of contact regarding the security of such software for nonfederal entities; and support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security. CISA must (1) publicly publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; and (2) update the framework at least annually. The bill provides for a critical infrastructure assessment study and pilot assessment. CISA's Cybersecurity Advisory Committee may establish a software security subcommittee, including open source software security. The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software.

Bill Text Versions

View Text
2 versions available

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Sep 21, 2022
Introduced in Senate
Sep 21, 2022
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sep 28, 2022
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Dec 19, 2022
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 117-278.
Dec 19, 2022
Placed on Senate Legislative Calendar under General Orders. Calendar No. 677.
  • September 21, 2022
    Introduced in Senate


  • September 21, 2022
    Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


  • September 28, 2022
    Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.


  • December 19, 2022
    Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 117-278.


  • December 19, 2022
    Placed on Senate Legislative Calendar under General Orders. Calendar No. 677.
Gary C. Peters

Gary C. Peters

Democratic Senator

Michigan

Cosponsors (1)
Rob Portman (Republican)

Homeland Security and Governmental Affairs Committee

Government Operations and Politics

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Advisory bodiesComputers and information technologyComputer security and identity theftCongressional oversightGovernment information and archivesGovernment studies and investigationsPerformance measurement