Joint Advisory: Securing Software Products Through Memory Safety

New Zealand’s National Cyber Security Centre (NCSC) and CERT NZ(external link) have issued a joint advisory in partnership with the United States of America's Cybersecurity and Infrastructure Security Agency (CISA)(external link), the National Security Agency (NSA)(external link), the Federal Bureau of Investigation (FBI)(external link), and the cybersecurity authorities of Australia, Canada, and the United Kingdom.

The Case for Memory Safe Roadmaps: Why Both C-Suite Executives and Technical Experts Need to Take Memory Safe Coding Seriously has been developed as part of the Secure by Design(external link) campaign. In this guidance the authoring agencies urge software manufacturer executives to reduce customer risk by prioritising design and development practices that implement memory safe programming languages (MSLs) in order to reduce memory safety vulnerabilities from products.

The guidance also urges software manufacturers to create and publish memory safe roadmaps that detail how they will eliminate memory safety vulnerabilities in their products and provides manufacturers with steps on how to create memory safe roadmaps and implement changes.

For more NCSC updates, follow us on LinkedIn(external link).