Comment from email: White House ATC RFC - comments from CISQ
- Dominant language
- CSS
- Stars
- 59
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
Mr. Liddell, Mr. Wilmer,
My name is Tracie Berardi, program manager of the Consortium for IT Software Quality (CISQ).
I read the IT Modernization report in support of EO 13,800. Thank you for making the notification and feedback loop on this plan as open, easy and efficient as possible. It’s great to write to you!
Key message up front: The Federal Government should use standards developed by CISQ to control the cyber security, resiliency, and overall risk of software-intensive systems developed internally or acquired by third parties.
The CISQ Metrics for Security, Reliability, Performance Efficiency and Maintainability, developed over the last nine years by subject matter experts in government and industry across US and Europe, are used to measure the occurrence of critical coding and architectural flaws in the source code of software-intensive systems. It’s the only actionable standard for measuring software characteristics, and it builds on other industry work, such as CWE, and maps to ISO 25000.
This year, the standards are being cited directly in Federal IT contracts.
From GSA, May 2017, Office of the CIO for the Office of Public Buildings statement of work for Project Based IT Services –
"PB-ITS (Project Based IT Services) is seeking to establish code quality standards for its existing code base, as well as new development tasks. As an emerging standard, PB-ITS references the Consortium for IT Software Quality (CISQ) for guidance on how to measure, evaluate and improve software."
The State Department’s $750M Consular Systems Modernization project in acquisition now cites a requirement for software quality standards.
New Texas State legislation has introduced software measurement standards into State IT performance and cybersecurity reporting, led by CISQ Advisor, Herb Krasner.
These examples are trailblazers and we expect to see more of them.
Jack – we look forward to hosting you at the Oct 19 Cyber Resilience Summit: Modernizing and Securing Government IT. How timely! Will be a good brief on CISQ. www.it-cisq.org
Dr. Bill Curtis, CISQ Executive Director, also read the report and asked that I forward you his comments – attached.
Best regards,
Tracie
Tracie Berardi
Program Manager
Consortium for IT Software Quality (CISQ)
[Fed IT Modernization - CISQ comments.docx](https://github.com/GSA/modernization/files/1323134/Fed.IT.Modernization.-.CISQ.comments.docx)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.