Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · REGISTER · 2024-10-29 · Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS) · Notices

Notices. Notice of availability; extension of comment period

467 words·~2 min read·/register/2024/10/29/2024-25078·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

BILLING CODE 4140-01-P DEPARTMENT OF HOMELAND SECURITY [Docket No. CISA-2024-0028] Request for Comment on Product Security Bad Practices Guidance AGENCY: Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS). ACTION: Notice of availability; extension of comment period. SUMMARY: On October 16, 2024, the Cybersecurity Division
(CSD)within the Cybersecurity and Infrastructure Security Agency
(CISA)published a request for comment in the **Federal Register** on the voluntary, draft Product Security Bad Practices guidance, which requests feedback on the draft guidance. CISA is extending the comment period for the draft guidance for an additional fourteen days through December 16, 2024. DATES: The comment period for the proposed voluntary guidance published on October 16, 2024, at 89 FR 83508 is extended. Comments and related materials must be submitted on or before December 16, 2024. ADDRESSES: You may submit comments, identified by docket number CISA-2024-0028, by following the instructions below for submitting comments via the Federal eRulemaking Portal at *https://www.regulations.gov.* *Instructions:* All comments received must include the agency name and docket number Docket Number CISA-2024-0028. All comments received will be posted without change to *http://www.regulations.gov,* including any personal information provided. CISA reserves the right to publicly republish relevant and unedited comments in their entirety that are submitted to the docket. Do not include personal information such as account numbers, social security numbers, or the names of other individuals. Do not submit confidential business information or otherwise sensitive or protected information. *Docket:* For access to the docket to read the draft Product Security Bad Practices Guidance or comments received, go to *https://www.regulations.gov.* FOR FURTHER INFORMATION CONTACT: Kirk Lawrence, 202-617-0036, *SecureByDesign@cisa.dhs.gov.* SUPPLEMENTARY INFORMATION: On October 16, 2024, CISA published a request for comment on voluntary, draft Product Security Bad Practices guidance (89 FR 83508). In the draft guidance, we provided an overview of product security practices that are deemed exceptionally risky, particularly for organizations supporting critical infrastructure or national critical functions (NCFs), and it provides recommendations for software manufacturers to voluntarily mitigate these risks. The guidance contained in the document is non-binding, and while CISA encourages organizations to avoid these bad practices, the document imposes no requirement on them to do so. The draft guidance is scoped to software manufacturers who develop software products and services, including on-premises software, cloud services, and software as a service (SaaS), used in support of critical infrastructure or NCFs. The request for comment provided for a 45-day comment period, set to close on December 2, 2024. CISA received requests to extend the deadline given the Thanksgiving holiday. Therefore, the comment period is now open through December 16, 2024. This notice is issued under the authority of 6 U.S.C. 652 and 659. Jeffrey E. Greene, Executive Assistant Director for Cybersecurity, Cybersecurity and Infrastructure Security Agency, Department of Homeland Security. [FR Doc. 2024-25078 Filed 10-28-24; 8:45 am]
Connectionstraces to 1
Citation graph
cites case law
Notices
Notice of availability; extension of comment period
Cites 1Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.