{domain:"www.qualitydigest.com",server:"169.47.211.87"} Skip to main content

        
User account menu
Main navigation
  • Topics
    • Customer Care
    • FDA Compliance
    • Healthcare
    • Innovation
    • Lean
    • Management
    • Metrology
    • Operations
    • Risk Management
    • Six Sigma
    • Standards
    • Statistics
    • Supply Chain
    • Sustainability
    • Training
  • Videos/Webinars
    • All videos
    • Product Demos
    • Webinars
  • Advertise
    • Advertise
    • Submit B2B Press Release
    • Write for us
  • Metrology Hub
  • Training
  • Subscribe
  • Log in
Mobile Menu
  • Home
  • Topics
    • 3D Metrology-CMSC
    • Customer Care
    • FDA Compliance
    • Healthcare
    • Innovation
    • Lean
    • Management
    • Metrology
    • Operations
    • Risk Management
    • Six Sigma
    • Standards
    • Statistics
    • Supply Chain
    • Sustainability
    • Training
  • Login / Subscribe
  • More...
    • All Features
    • All News
    • All Videos
    • Contact
    • Training

NIST Consortium and Draft Guidelines Aim to Improve Security in Software Development

Submit comments on guidelines by Sept. 12, 2025

NIST

NIST
Thu, 08/28/2025 - 12:02
  • Comment
  • RSS

Social Sharing block

  • Print
Body

To support the creation of software that is secure against cyber-breaches and free of malicious code, the U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) is working with industry partners through a consortium focused on improving software security. 

ADVERTISEMENT

The Software Supply Chain and DevOps Security Practices Consortium is part of NIST’s response to White House Executive Order (EO) 14306, Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 (Rebranding United States Foreign Assistance to Advance American Influence) and Executive Order 14144 (Strengthening and Promoting Innovation in the Nation’s Cybersecurity.)

As stipulated in the EO, the consortium will develop guidelines that demonstrate the implementation of best practices based on NIST’s Secure Software Development Framework (SSDF).

Led by NIST’s National Cybersecurity Center of Excellence (NCCoE), the consortium includes 14 member organizations.

The group’s objective is to develop guidelines that will help improve security at all stages of the software development life cycle, from a software product’s initial planning and testing to its deployment, operation, and maintenance in real-world environments.

Draft guidelines for public comment

The NCCoE has released a preliminary draft of these guidelines, “Secure Software Development, Security, and Operations (DevSecOps) Practices” (NIST Special Publication (SP) 1800-44), for public comment. The current version provides a high-level overview of the project. Future iterations will include a detailed reference model and specific implementation guidelines for each of the project’s planned use cases.

The publication aligns with and expands on the SSDF, which NIST released in 2022. While the SSDF provides a core set of high-level secure software development practices, it doesn’t go into detail about how an organization might create a secure development environment that fits the organization’s objectives. SP 1800-44 will complement the SSDF by offering specific examples of how to create that environment, leading to consistently trustworthy and quicker software development.

“The SSDF looks at building software holistically, helping organizations figure out what needs to be done to make their development environment more secure, how to protect it, and find deficiencies that make it vulnerable,” says NCCoE’s Alper Kerman, one of the publication’s authors. “The draft guidelines we’re developing will show how organizations can use commercial, off-the-shelf technologies and AI capabilities, and apply zero trust principles and methodologies to create an efficient and secure development environment for producing fast and more reliable software.”

Development environments with security practices in place allow teams to collaborate during the creation of software while preventing unauthorized individuals from accessing their work. These environments are growing in importance as vulnerabilities can crop up at every stage in the software development life cycle.

“You have to have an environment to write code in, where the whole team of developers can access it and update the code in an agile fashion,” Kerman says. “But when you’re writing code, a team member might bring in code libraries from other parties, for example. We’ll outline best practices for minimizing the likelihood that vulnerabilities might creep in as a result, such as effective ways to scan the code for trouble spots.”

NIST is accepting comments online from the public on the preliminary draft guidelines until Sept. 12, 2025. The agency plans to release additional drafts of the guidelines incrementally throughout the life of the project, accompanied by public comment periods.

For those interested in contributing to the development of the draft guidelines, NIST is planning a virtual event for Aug. 27, 2025, at 1 p.m. Eastern to highlight the project’s goals, as well as gather feedback and additional insight for the project.

Registration for the event is available online. In addition, NIST invites the public to join its Community of Interest. Participation in the project is open to all interested organizations. For more information, write to NCCoE-DevSecOps@list.nist.gov. 

Published July 30, 2025, by NIST.

Add new comment

The content of this field is kept private and will not be shown publicly.
About text formats
Image CAPTCHA
Enter the characters shown in the image.

© 2025 Quality Digest. Copyright on content held by Quality Digest or by individual authors. Contact Quality Digest for reprint information.
“Quality Digest" is a trademark owned by Quality Circle Institute Inc.

footer
  • Home
  • Print QD: 1995-2008
  • Print QD: 2008-2009
  • Videos
  • Privacy Policy
  • Write for us
footer second menu
  • Subscribe to Quality Digest
  • About Us
  • Contact Us