GSA / GSA/modernization

Comment from email: White House ATC RFC - comments from CISQ

Open
#86 1 comment 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Mr. Liddell, Mr. Wilmer,

My name is Tracie Berardi, program manager of the Consortium for IT Software Quality (CISQ).

I read the IT Modernization report in support of EO 13,800. Thank you for making the notification and feedback loop on this plan as open, easy and efficient as possible. It’s great to write to you!

Key message up front: The Federal Government should use standards developed by CISQ to control the cyber security, resiliency, and overall risk of software-intensive systems developed internally or acquired by third parties.

The CISQ Metrics for Security, Reliability, Performance Efficiency and Maintainability, developed over the last nine years by subject matter experts in government and industry across US and Europe, are used to measure the occurrence of critical coding and architectural flaws in the source code of software-intensive systems. It’s the only actionable standard for measuring software characteristics, and it builds on other industry work, such as CWE, and maps to ISO 25000.

This year, the standards are being cited directly in Federal IT contracts.

From GSA, May 2017, Office of the CIO for the Office of Public Buildings statement of work for Project Based IT Services –

"PB-ITS (Project Based IT Services) is seeking to establish code quality standards for its existing code base, as well as new development tasks. As an emerging standard, PB-ITS references the Consortium for IT Software Quality (CISQ) for guidance on how to measure, evaluate and improve software."

The State Department’s $750M Consular Systems Modernization project in acquisition now cites a requirement for software quality standards.

New Texas State legislation has introduced software measurement standards into State IT performance and cybersecurity reporting, led by CISQ Advisor, Herb Krasner.

These examples are trailblazers and we expect to see more of them.

Jack – we look forward to hosting you at the Oct 19 Cyber Resilience Summit: Modernizing and Securing Government IT. How timely! Will be a good brief on CISQ. www.it-cisq.org

Dr. Bill Curtis, CISQ Executive Director, also read the report and asked that I forward you his comments – attached.

Best regards,
Tracie

Tracie Berardi
Program Manager
Consortium for IT Software Quality (CISQ)
[Fed IT Modernization - CISQ comments.docx](https://github.com/GSA/modernization/files/1323134/Fed.IT.Modernization.-.CISQ.comments.docx)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.