security1 distinct publisher
CISA and the FBI put "exceptionally risky" software practices in writing, and buyers get the list
The guidance is non-binding. It is also a named list a critical-infrastructure buyer can read back to a vendor, starting with memory-unsafe code and the published plan for getting out of it.
Publishers:cisa.gov
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+12
- Incentives52
- Confidence64