Cybersecurity

Tidelift Public Sector Momentum Increases as Cybersecurity Supply Chain Risk Management Becomes Top Government Priority

Businesswire | May 30, 2023 | Read time : 06:30 min

Tidelift Public Sector Momentum Increases as Cybersecurity Supply Chain Risk Management

Tidelift, a provider of solutions for improving the security and resilience of the open source software powering modern applications, today announced that it has been awarded three U.S. government contracts worth over $3.5 million, and is expanding its public sector organization in response to increased demand for innovative solutions that help the U.S. government improve its cybersecurity supply chain risk management (C-SCRM) capabilities.

High-profile software supply chain vulnerabilities including Log4Shell and SolarWinds have dramatically increased attention on the need for improved software security, both in the public sector and beyond. In the U.S., this effort began in May, 2021 with White House Executive Order 14028: Improving the Nation’s Cybersecurity, and since then a variety of policy and legislative initiatives around cybersecurity have gained traction.

In September, 2022, the U.S. government’s Office of Management and Budget released memorandum M-22-18 on Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. M-22-18 formalizes the guidance provided in the NIST Secure Software Development Framework and NIST Software Supply Chain Security Guidance documents as the government requirements for developing secure software, and mandates federal government agencies comply with these guidelines.

This memorandum sets aggressive deadlines for compliance with specific dates for both government agencies and organizations selling software to the government to comply with NIST guidelines. Among other stipulations, it requires that any organization selling software to the government must self-attest that their software is compliant with the NIST SSDF by June 2023 for critical software or by September 2023 for all other software.

More recently, the National Cybersecurity Strategy sets a new precedent for software security liability, with the government intending to hold software producers liable for damages caused by preventable security vulnerabilities and offer liability protections to organizations that can show they follow secure software development practices.

Tidelift awarded three U.S. government contracts worth over $3.5 million

In addition to efforts like those mentioned above, the U.S. government is increasingly investing directly in improving open source software security. Tidelift was recently awarded three separate innovation research awards as part of the U.S. government SBIR program. The SBIR program is designed to help U.S.-based businesses invest in their technical potential, while stimulating technology innovation and meeting specific research and development needs.

Through these SBIR Phase II awards, Tidelift is working with the Department of the Air Force and the Defense Advanced Research Projects Agency (DARPA) to help spur innovation in the systems and processes the U.S. government uses to improve open source software security and cybersecurity supply chain risk management. This investment will help Tidelift expand its industry-leading open source software management solution, including increasing its ability to partner with even more open source maintainers to validate their components meet important security, maintenance, and licensing standards required by government and industry users, and pay these maintainers for this critical work.

It will also help the U.S. government better address the requirements and deadlines emerging from Executive Order 14028, memorandum M-22-18, and the NIST Secure Software Development Framework, especially when it comes to the open source components in use in government applications. Tidelift is also helping address new requirements around software bills of materials (SBOMs) that U.S. government agencies are beginning to understand, interpret, plan for, and deploy. Along with Tidelift producing an SBOM from every application build, the company is actively working upstream with open source maintainers to validate and improve security, maintenance, and licensing metadata for their projects and capture this data using the TACOS (Trusted Attestation and Compliance for Open Source) attestation framework.

"The United States Air Force, and the Government as a whole, are among the largest consumers of open source software. With the increasing requirements around Software Supply Chain Risk Management (SCRM) and Software Bills of Materials (SBOM) initiatives, we are excited to partner with Tidelift to enhance cybersecurity resilience outcomes for open source software dependencies that support our most critical work," said Robert "Devo" DeVincent, Chief Software Officer, Air Force 309th Software Engineering Group.

Tidelift expands public sector organization to meet growing demand

Tidelift has named Matthew Arnow, a long-time veteran of Tidelift, to lead the newly expanded public sector team. Matthew heads up the team with extensive experience working with government and public sector clients.

“Tidelift looks forward to working more closely with our government and public sector customers and prospects to improve the resilience of our mission-critical open source infrastructure,” said Matthew Arnow, head of public sector for Tidelift. “Our unique approach of working directly with the maintainers behind thousands of important open source projects will help public sector customers comply with U.S. government security directives and meet necessary government and industry standards.”

Tidelift partners with Carahsoft to support public sector expansion

Tidelift has also partnered with Carahsoft, the leading government reseller partner, to help more quickly and effectively address the number of large public sector opportunities.

“Over the past year, we’ve seen increased demand from our customers for solutions that help improve open source software security and supply chain resilience,” said Natalie Gregory, vice president, Carahsoft. “We look forward to working with Tidelift and our reseller partners to deliver open source software supply chain risk management solutions to our government customers.”

About Tidelift

Tidelift, a 2022 Gartner Cool Vendor, helps organizations effectively manage the open source behind modern applications. Through the Tidelift Subscription, the company delivers the tools, data, and strategies powering an inclusive and organization-wide approach to improving the health and security of the open source software supply chain. Tidelift enables organizations to move fast and stay safe when building applications with open source, so they can create more incredible software, even faster. https://tidelift.com/

Spotlight

Spotlight

Related News

Emerging Technology, Cybersecurity

OwnBackup Achieves FedRAMP® Authorized Designation

Businesswire | July 20, 2023

OwnBackup, the leading SaaS data protection platform, today announced it has achieved FedRAMP® authorization for its OwnBackup Government Cloud solution. With this authorization, OwnBackup is now listed on the FedRAMP® Marketplace, and is eligible to provide data protection services to all U.S. Federal Government customers. Established in 2011, FedRAMP® is a government-wide program that promotes the adoption of secure Cloud services across the Federal Government, forming a public-private partnership to promote innovation and the advancement of more secure information technologies. By achieving FedRAMP® authorization, OwnBackup has demonstrated that it meets the rigorous security and compliance requirements of the program to host sensitive information in the Cloud. “FedRAMP® authorization is a significant milestone for OwnBackup, and reaffirms our position as the market leader in SaaS data protection,” said Sam Gutmann, Chief Executive Officer at OwnBackup. “This designation allows us to bring our best-in-class solutions to Federal Government agencies, partnering with these vital organizations to accelerate their digital transformation goals, while ensuring that critical Federal Data and Metadata remains secure.” OwnBackup’s FedRAMP® announcement comes at a time when the U.S. Government is making cybersecurity a clear priority. Earlier this year, the Biden-Harris Administration announced a new National Cybersecurity Strategy focused on strengthening the Nation's digital infrastructure, emphasizing the importance of Cloud security and resilience, and protecting citizens and businesses from cyber threats. While no individual or company is immune to cyber threats, these attacks disproportionately target the public sector. The public sector manages a wide array of sensitive information, making it a popular target for cyber criminals. According to Verizon’s 2022 Data Breach Investigations Report (DBIR), the public sector had the second most attacks of any industry. With OwnBackup, U.S. Government Agencies can be better prepared to avoid disruption to critical services, ensure a continuity of operations, and uphold trust and confidence with the citizens that they serve. OwnBackup’s Data Protection Platform, which is used by over 6,000 customers across critical SaaS ecosystems, was designed with security in mind from its inception. OwnBackup’s solutions are architected with a variety of security controls across multiple tiers to address a range of security risks. About OwnBackup OwnBackup is a leading SaaS data protection platform for some of the largest SaaS ecosystems in the world, including Salesforce, Microsoft Dynamics 365, and ServiceNow. Through capabilities like data security, backup and recovery, archiving, and sandbox seeding, OwnBackup empowers thousands of organizations worldwide to manage and protect the mission-critical data that drives their business. Co-founded by seasoned data recovery, data protection, and information security experts, OwnBackup is a trusted independent software vendor (ISV) partner on the Salesforce AppExchange, AWS Marketplace, and Microsoft Marketplace. The Company is headquartered in Englewood Cliffs, New Jersey, with research and development (R&D), support, and other functions in Israel, EMEA and APAC. OwnBackup has raised over $500 million in venture funding, is ranked on the Forbes Cloud 100 as one of the world's top private cloud companies, and is the partner of choice for some of the world’s largest users of SaaS applications.

Read More

Emerging Technology

Pexip Government Cloud Attains StateRAMP Authorization

PR Newswire | August 07, 2023

Pexip, a company that provides multi-platform software video technology, announced that its Pexip Government Cloud (PGC) Cloud Service Offering (CSO) has received StateRAMP Authorized status in the Moderate security categorization from the StateRAMP Project Management Office (PMO) and the StateRAMP Approvals Committee (SAC). In April, Pexip received an Authority to Operate (ATO) at the Moderate Impact level from the Federal Risk and Authorization Management Program (FedRAMP), sponsored by the U.S. Department of Labor. The StateRAMP Authorization enables secure and compliant collaboration for state and local agencies on Microsoft Teams. Employees can easily join Microsoft Teams calls using Cloud Video Interop (CVI) from video conferencing systems in meeting rooms or from personal devices, whether from the office or home making collaboration seamless an efficient. Pexip also enables state and local agencies to manage their existing video infrastructure investments, making it a cost-effective solution. "We are very excited about our StateRAMP authorization and believe it represents another great example of Pexip's commitment to delivering secure and compliant solutions to our government customers," said Peter McCarthy, VP of Public Sector, Pexip. As agencies move to the cloud, Pexip stands ready to support them at every stage. The StateRAMP-authorized Pexip Government Cloud (PGC) platform offers secure video conferencing as a service, ensuring agencies can engage in productive collaboration while adhering to rigorous security standards. For agencies with the most stringent security requirements, such as On-Premise mandates or GCC-High Teams Tenants, Pexip offers the option to self-host its software. This enables complete data control and interoperability within these specialized environments. Pexips StateRAMP approval is a testament to its commitment to delivering safe and compliant solutions to its government customers. Pexip's StateRAMP approval includes: US Department of Defense (DoD) Unified Capabilities Approved Product List (UC APL) authorized Cryptographic Module Validation Program (CMVP) validated Federal Information Processing Standard (FIPS) 140-2 module #3503 ISO/IEC 27001:2013 certified Section 508 compliant General Data Protection Regulation (GDPR) compliant Supports Health Insurance Portability and Accountability Act (HIPAA) compliance Supports zero trust security architectures About Pexips Pexip enables enterprises and organizations of any size to deploy and use video-based communication and collaboration. The Company’s portfolio of products ranges from self-hosted software to cloud service video solutions. Pexip provides seamless collaboration between previously incompatible video and audio technologies such as professional video conferencing systems, Skype for Business, Microsoft Teams, Google Hangouts Meet, and WebRTC. Pexip’s software-based meeting platform can also be used as a foundation for service provider offerings. Pexip has HQ in Oslo, Norway, main offices in London, UK, New York and Reston, US and Sydney, Australia, as well as sales offices across the globe.

Read More

Emerging Technology

Telos Corporation Awarded Five-Year Contract with Defense Information Systems Agency

GlobeNewswire | August 29, 2023

Telos Corporation, a leading provider of cyber, cloud and enterprise security solutions for the world’s most security-conscious organizations, announced today a five-year contract with the Defense Information Systems Agency (DISA) for the Telos Automated Message Handling System (AMHS) to support the distribution and processing of various reports and other critical information. A widely-used organizational messaging solution in the U.S. Department of Defense, Telos AMHS supports organizations around the world, including the Joint Chiefs of Staff, Combatant Commands, Military Services, Defense Agencies and the Intelligence Community. Telos AMHS immediately routes incoming messages to the right desktop and creates an archive of all arriving traffic for future reference. AMHS also provides intuitive tools for searching and retrieving messages from the archive while protecting against unauthorized access, and offers an easy way to create, coordinate, and release outgoing messages. “DISA is one of our longest-standing customers, and we’re pleased to continue to support their organizational communications,” said John B. Wood, CEO and chairman, Telos. “Timely and secure message delivery is key to successful military operations, and we’re honored to be chosen to support this mission.” About Telos Corporation Telos Corporationempowers and protects the world’s most security- conscious organizations with solutions for continuous security assurance of individuals, systems, and information. Telos’ offerings include cybersecurity solutions for IT risk management and information security; cloud security solutions to protect cloud-based assets and enable continuous compliance with industry and government security standards; and enterprise security solutions for identity and access management, secure mobility, organizational messaging, and network management and defense. The company serves commercial enterprises, regulated industries and government customers around the world.

Read More