FHFA should update FHFA’s Supply Chain Risk Management Strategy to include past due OMB M-22-18 requirements including: i. Obtaining a self-attestation from the software producer before using the software; ii. Obtaining from software producers artifacts that demonstrate conformance to secure software development practices, as needed; iii. Establishing a system to store self-attestation letters from the software producer that are not publicly available in a central location; and iv. Assessing and developing training for reviewing and validating self-attestation letters.
