Feds Prioritize Open-Source Software Security Initiatives
With the first open-source office established at CMS, a White House-led open-source group aims to advance many other initiatives in 2025.

A White House working group comprising federal agencies released a series of initiatives it will tackle regarding ongoing work to secure open-source software as the technology becomes more critical to combatting growing security concerns following high-profile cyberattacks like Log4j and SolarWinds.
Some of the initiatives over the upcoming fiscal year include forging partnerships within government and globally, further developing software bills of material (SBOMs), strengthening the supply chain and creating government’s first open-source program office at the Centers for Medicare and Medicaid Services.
The updates came as part of an August summary report of a 2023 request for information on open-source software security put forth by the Open-Source Software Security Initiative, an interagency group comprising representatives from the Office of the National Cyber Director, Cybersecurity and Infrastructure Security Agency (CISA), National Science Foundation, DARPA and the Office of Management and Budget (OMB).
National Cyber Director Harry Coker highlighted the evolving landscape around open source within the federal government in his opening remarks at DefCon in August.
“We know that open source underlies our digital infrastructure, and it’s vital that, as a government, we contribute back to the community as part of our broader infrastructure efforts,” said Coker.
He cited how policymakers are increasingly turning to the security research community to solve cybersecurity challenges, resulting in efforts like NSA’s Cybersecurity Collaboration Center, CISA’s Joint Cyber Defense Collaborative and government’s first open-source program office.
Government’s First Open-Source Program Office
Momentum around open-source software security grew from the March 2023 National Cybersecurity Strategy and subsequent implementation plans followed by the Bipartisan Infrastructure Law providing incentives for investments in advanced cybersecurity technology.
For government’s first open-source program office, CMS has long seen this coming.
“CMS has been on an open-source journey for many years. We don’t want to be reinventing the wheel,” CMS Open Source Lead Remy DeCausemaker told GovCIO Media & Research.
DeCausemaker said this journey initially began with the Affordable Care Act with Department of Health and Human Services data repositories dating back to 2011 and included major initiatives such as the Blue Button API, data at the point of care, the AB2D [API] and the beneficiary FHIR database server.
“We’ve been on our open-source journey here at CMS for well over a decade, starting in sort of the era of healthcare.gov. The sort of crown jewels of CMS’ open-source journey is on developer.cms.gov,” said DeCausemaker.
The office is currently focused on establishing and maintaining guidance, policies, practices and talent pipelines at CMS, HHS and the rest of the federal open-source community.
DeCausemaker emphasized these programs will mature as it learns about the unique needs across agencies.
“All of [the offices at HHS] have their own cybersecurity policies and infrastructure teams. The open-source program office serves as a bridge between the different parts of the agency,” said DeCausemaker. “We are helping to make it easier to implement and follow the guidelines that come from places like our own information security and privacy group, but also keeping an eye on things coming down from CISA.”
CISA Senior Technical Advisor Jack Cable said CISA is working on its own open-source program office using CMS as a lighthouse. CISA also plans to create guidance for other agencies to do the same.
“We are actively working on voluntary guidance to federal agencies around establishing open-source program offices,” said Cable. “Our goal isn’t to control or regulate open-source software, but rather show up as a community member and contribute where we can with government’s resources.”
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
The Next AI Wave Requires Stronger Cyber Defenses, Data Management
IT officials warn of new vulnerabilities posed by AI as agencies continue to leverage the tech to boost operational efficiency.
5m read -
Federal CIOs Push for ROI-Focused Modernization to Advance Mission Goals
CIOs focus on return on investment, data governance and application modernization to drive mission outcomes as agencies adopt new tech tools.
4m read -
Fed Efficiency Drive Includes Code-Sharing Law, Metahumans
By reusing existing code instead of rewriting it, agencies could dramatically cut costs under the soon-to-be-enacted SHARE IT Act.
5m read -
DOD Can No Longer Assume Superiority in Digital Warfare, Officials Warn
The DOD must make concerted efforts to address cyber vulnerabilities to maintain the tactical edge, military leaders said at HammerCon 2025.
4m read -
Tracking CIOs in Trump's Second Term
Stay informed on the latest shifts in federal technology leadership as new CIOs are appointed and President Trump's second term takes shape.
6m read -
IRS Makes Direct File Code Public as Lawmakers Debate Program’s Fate
The agency sees the Direct File source code as beneficial to government digital services despite what happens with it in proposed budgets.
5m read -
Inside Oak Ridge National Lab’s Pioneer Approach to AI
Energy Department’s Oak Ridge National Lab transforms AI vulnerabilities into strategic opportunities for national defense.
22m listen -
AWS Summit: Innovation Accelerates IT Delivery at DOD
Marine Corps Community Services is tackling outdated IT processes with agile development and cutting-edge cloud security to deliver mission-critical capabilities faster.
12m watch -
AWS Summit: NIST Secures High-Performance Computing Against Evolving Threats
NIST’s Yang Guo reveals the broad attack surface of high-performance computing and explains developing guidance and future-proofing security strategies.
9m watch -
Trump Overhauls Federal Cybersecurity with New Executive Order
The new directive aims to strengthen digital defenses while rolling back "burdensome" software requirements and refocusing AI security.
3m read -
AWS Summit: Forging Successful Cloud Modernization Partnerships
Industry leaders share insights on the critical role industry partnerships have in enabling government agencies to navigate procurement challenges for cloud and zero trust solutions.
24m watch Partner Content -
CISA's CVE Program and Why it Matters for Zero Trust
The vulnerability program provides the cybersecurity community visibility into software as part of a key pillar of CISA's zero trust model.
5m read