techUK response to the call for views on the Code of Practice for Software Vendors

techUK took a thematic approach to its response and after consulting members highlighted a number of recommendations to government, a snapshot of these are outlined below:
Members agreed that the guidance should be a Code of Practice and not a ‘standard’ and would like to see this reflected in the terminology used throughout the document, avoiding ‘requirements’ and using the definition from BS0 of British Standards Institute (BSI).
Concerns were raised about the shortage of cyber-specific personnel and the lack of awareness about required skills. Collaboration between government and industry as an essential tool to build the necessary skills base, ensuring supplier diligence and best practices across all organisations.
Government should ensure the Code drives best practices without increasing the burden on organisations and as code restricted to substitutable recommendations so that it can work across multiple contexts of use and maximise compatibility with existing standards.
More alignment is needed with international partners and with Code of Practice documents the government have already published and are currently consulting on.
To ensure there is good uptake of the cyber security principles, government must continue to work with industry to promote the education and awareness of its importance.
For a more detailed understanding of techUK's recommendations, please read full consultation response.
techUK Response DSIT Software Vendors Call for Views FINAL.pdf



