CIO Influence
CIO Influence News Security

Aqua Security Offers Only Enterprise-Grade Software Supply Chain Solution to Meet Executive Order 14028

Aqua Security More Than Doubles Revenue

Aqua helps software vendors meet compliance requirements in under 30 days to prepare for 2023 deadline

Aqua Security, the leading pure-play cloud native security provider, announced that it is the only enterprise-grade vendor providing software supply chain security attestation to meet the requirements of Executive Order (EO) 14028. The Executive Order on Improving the Nation’s Cybersecurity lists out all the software supply chain requirements that third-party software companies must meet or exceed to enhance the nation’s cybersecurity and protect the nation from malicious cyber actors.

“This order has a vast impact on global software suppliers. If you sell to the government, or you sell to a company that sells to the government, you need to prove compliance,” explains Dror Davidoff, CEO and cofounder of Aqua Security. “As software supply chain attacks increase in sophistication and scale, the private sector must adapt its proactive cybersecurity measures. EO 14028 is a critical and bold step for the United States to help prevent cyber incidents.”

Latest ITechnology News: ETSI Secures Critical Infrastructures against Cyber Quantum Attacks with new TETRA Algorithms

Following EO 14028, in September 2022, a memo Enhancing the Security of the Software Supply Chain through Secure Software Development Practices was released listing the effective dates for agencies to ensure that the software they are procuring (and have previously procured) is compliant with the EO. Deadlines are as follows:

  • By January 12, 2023 – Agency CIOs to communicate requirements to vendors
  • By June 11, 2023 – Compliance attestation letters to be collected for critical software
  • By September 14, 2023 – Compliance attestation letters to be collected for all software

Latest ITechnology News: NetAlly Launches AirCheck G3 Wi-Fi 6 Wireless Analyzer

Meeting EO and Software Bill of Materials (SBOM) Compliance with Aqua

Aqua Security’s Software Supply Chain Security is the only end-to-end solution that ensures protection across the entire software development lifecycle and will enable software providers to meet and attest to the EO requirements. The solution helps companies to complete compliance requirements within a month of deployment and includes the reporting and management capabilities for initial and ongoing compliance attestation. Specifically, the Aqua Solution ensures compliance with EO 14028 by:

  • Ensuring secure configuration of development environments with accompanying attestation (sections 4e i-ii)
  • Ensuring sources of code are trusted and that code vulnerabilities have been remediated with accompanying attestation (sections 4e iii-v)
  • Maintaining provenance data for internal and third-party code and having an SBOM for each released product (sections 4e vi-vii)
  • Maintaining secure development processes with accompanying attestation (section 4e ix)
  • Maintaining data integrity and provenance of open source software in use with accompanying attestation (section 4e x)

“The clock is ticking—we are only 10 months away from the compliance deadline. Aqua is making it easy for software vendors to not only meet compliance requirements but also have the confidence that they can prevent software supply chain attacks,” said Davidoff.

Latest ITechnology News: Snowflake Disrupts Application Development with General Availability of Snowpark for Python, Native Streamlit Support

[To share your insights with us, please write to sghosh@martechseries.com]

Related posts

IRALOGIX Selects ProNvest to Create a Fully Integrated Managed Account IRA Solution

Axonius Named One Of 25 Highest-Rated Private Cloud Computing Companies To Work For

CIO Influence News Desk

Dockworks Names New CTO to Build a Culture of Continuous Innovation