Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Biden Administration Deploys Executive Order Seeking To Protect Software Supply Chains

CRN by CRN
January 17, 2025
Home News
Share on FacebookShare on Twitter


The last-minute effort from the outgoing administration includes new requirements for software vendors that supply the federal government.

The last-minute cybersecurity executive order from the outgoing Biden administration, signed by President Joe Biden Thursday, includes several new requirements for software vendors that supply the federal government.

While existing efforts from the White House have sought to improve software security in connection with government procurement—such as Biden’s cybersecurity-focused Executive Order 14028 from 2021—the requirements in the new executive order go further, according to Wei Chen, chief legal officer at cybersecurity vendor Infoblox.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

The order is “putting additional muscle behind the things that have already been proven and identified as best practice,” Chen, who had seen a draft version of the order, said in an interview.

The new requirements for software providers that do business with the federal government are aimed at bolstering the security of software supply chains and reducing vulnerabilities that could impact federal agencies.

The requirements include needing to provide “machine-readable secure software development attestations” as well as “high-level artifacts to validate those attestations” and “a list of the providers’ Federal Civilian Executive Branch (FCEB) agency software customers,” according to the Biden administration’s post about the new executive order.

The order requires the director of the Office of Management and Budget (OMB) to recommend new contract language—which will require software vendors to submit the attestations and other required items—within 30 days to the Federal Acquisition Regulatory Council (FAR Council).

Software providers will be required to submit the attestations, artifacts and customer lists to the Cybersecurity and Infrastructure Security Agency (CISA), according to the White House post about the order.

White House executive orders can be ignored by the next administration, and the order comes days before President Donald Trump is set to be inaugurated on Jan. 20.

However, Chen told CRN she is optimistic that the order will still end up having an impact.

“I don’t see anything that is not bipartisan [in the order],” she said. “And cybersecurity is a bipartisan issue.”

In addition to boosting software security, the executive order includes a number of additional measures related to protecting the federal government—such as requiring the use of phishing-resistant authentication within federal agencies and obligating agencies to enable encrypted DNS protocols within 180 days.

Nation-State Attacks Continue

The backdrop to the order is that “adversarial countries and criminals continue to conduct cyber campaigns targeting the United States and Americans, with the People’s Republic of China presenting the most active and persistent cyber threat to United States Government, private sector, and critical infrastructure networks,” the White House post on the order said.

“More must be done to improve the Nation’s cybersecurity against these threats,” the post said.

A series of state-sponsored attacks in recent years have impacted the U.S. government, among the widely felt SolarWinds Orion software supply chain compromise of 2020.

More recently, at least nine U.S. telecommunications providers were impacted in last year’s attacks by the China-linked espionage group tracked as Salt Typhoon—through which some federal officials saw their communications compromised, according to U.S. officials.



Source link

Tags: Cybersecurity
CRN

CRN

Next Post
StaffDNA®; LiquidAgents CEO Sheldon Arora Named to the 2025 SIA Staffing 100 North America List

StaffDNA®; LiquidAgents CEO Sheldon Arora Named to the 2025 SIA Staffing 100 North America List

Recommended.

WD Unveils Hard Drive Road Map: 100-TB-Plus Capacity, AI-Focused Innovations

WD Unveils Hard Drive Road Map: 100-TB-Plus Capacity, AI-Focused Innovations

February 4, 2026
Stocks making the biggest moves premarket: USA Rare Earth, Estee Lauder, Rocket Lab and more

Stocks making the biggest moves premarket: USA Rare Earth, Estee Lauder, Rocket Lab and more

October 13, 2025

Trending.

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

April 3, 2026
Openreach Taps Google Cloud AI to Accelerate High-Speed Internet Access and Cut Carbon

Openreach Taps Google Cloud AI to Accelerate High-Speed Internet Access and Cut Carbon

March 25, 2026
Viettel Marks 20 Years of Global Expansion, Overseas Revenue Up 25%

Viettel Marks 20 Years of Global Expansion, Overseas Revenue Up 25%

April 3, 2026
守正笃行:IBM 张榕解码 AI 时代的组织变革与人才之道

守正笃行:IBM 张榕解码 AI 时代的组织变革与人才之道

April 3, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio