The Open Source Security Foundation (OpenSSF) has announced the initial release of the Open Source Project Security Baseline (OSPS Baseline), a new initiative designed to help open source projects enhance their security posture. The OSPS Baseline provides a set of tiered best practices that are aligned with global cybersecurity frameworks, including the EU Cyber Resilience Act (CRA) and the NIST Secure Software Development Framework (SSDF). This alignment makes it easier for maintainers and contributors to adopt practical security measures that are recognized by industry and government.
The baseline is divided into three tiers:
- Tier 1: Foundational Security: This tier focuses on essential security practices that all open source projects should implement, such as vulnerability management, secure coding practices, and access control.
- Tier 2: Enhanced Security: This tier builds on the foundational practices with more advanced security measures, such as automated security testing, threat modeling, and supply chain security.
- Tier 3: Proactive Security: This tier is for projects that want to achieve the highest level of security. It includes practices such as a dedicated security team, regular security audits, and a formal security governance process.
The OSPS Baseline is a valuable resource for open source projects of all sizes. By adopting the baseline, projects can improve their security posture and reduce their risk of being compromised. The OpenSSF is encouraging all open source projects to adopt the OSPS Baseline and to provide feedback on how it can be improved.