Government publishes response to software resilience and security call for views

30 Jan 2024 01:43 PM

The government has responded to last Spring’s call for views on software resilience and security for businesses and organisations which sought views on: the range of risks linked to software; what was already being done to manage the associated risks; and what further action government would be most effective at taking to drive improvements.

The response sets out a package of policy interventions that the government intends to take forward in the coming months and years. These interventions will empower organisations who develop, sell and buy software to better understand their responsibilities and take action to reduce risk, thereby improving standards of software security throughout our supply chains.

Key themes from the call for views

Feedback gathered from stakeholders throughout the call for views process focused on the following themes, which outline different core risks and opportunities:

3 key areas of priority moving forward

In its response, government identifies three key areas of priority to help improve software security practices and protect the security and resilience of organisations across the UK, which reflect the key themes heard in the call for views:

  1. Setting clear expectations for software vendors -  secure and consistent standards are needed for companies which create and sell software.

          How will government address this?

  1. Strengthening accountability in the software supply chain - the purchasers of software need to have effective security practices and mechanisms to hold software vendors accountable through contractual requirements.

          How will government address this?

  1. Protecting high risk users and addressing systemic risks - public sector software development and use is a particular priority in terms of its higher risk context. It is also important that government leads by example in its own practices in order to support the improvements that our proposed interventions seek to drive across all sectors. Of particular importance will be assessing and improving the resilience of free and open source software which is vital to protecting technologies developed for use in both public and private sector contexts.

          How will government address this?

techUK very much looks forward to engaging with government on the proposed Code of Practice for Software Vendors and supporting interventions.  

You can read the full response to government’s call for views on software resilience and security here.