Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Offshore Software Development topic

No spam. Unsubscribe anytime.

State IT leaders warn of security and ethical risks from offshore software development

2647571 · March 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

State IT officials told the committee that offshore software coding resources present cybersecurity, third-party and ethical risks; the state is developing policy guidance and looking to models used by other states for exception processes.

State Chief Information Officer Terrence Woods and State Chief Information Security Officer Ben Goreski briefed the Joint Legislative Committee on Information Management and Technology about the state’s approach to proposed use of offshore software development resources on March 14.

Woods said the state has not finalized a policy but has studied offshore development and its tradeoffs: "we have not landed or completed a policy on this yet. However, we have done a lot of homework," he said. "There are benefits, some of them financial ... but there's also some risks that we want to talk to you about today."

The nut graf: officials told the committee offshore coding resources—where a vendor uses employees or subcontractors located in other countries to write or maintain software—can reduce cost and accelerate delivery but also raise security vulnerabilities, third-party risks and ethical questions that state policy must address.

In his briefing, Goreski described the principal cybersecurity risks: code produced offshore can embed vulnerabilities; vendors subject to foreign laws and oversight are harder to enforce; and subcontracting chains can create unvetted third-party access. "If you've got an offshore development ... operate under different laws and guidelines ... enforcing that in other countries is difficult," Goreski said. He said the state discourages offshore development for systems that handle particularly sensitive data, citing examples such as criminal-justice information systems.

Committee members asked how the state currently evaluates offshore proposals. Woods and staff said the state generally learns of offshore arrangements during the procurement "stage gate" process and currently raises security and ethics questions with agencies, but there is no mandatory statewide policy. Woods described outreach to the National Association of State Chief Information Officers (NASCIO) peer states; he said Virginia’s model, which uses a standard assessment and control specifications for exception requests, is the model Oregon is considering.

Members also asked whether ethical concerns—background checks, labor practice differences and potential human-rights issues—are part of the vetting process. Goreski said ethics are considered in vendor selection because values and regulatory regimes differ across countries: "When we hire, developers or any contractors, we ... go through background checks to make sure these folks have some integrity and ethics ... When you go outside of the side of the country, the values may not be the same. And therefore, they do introduce some risks."

Representative Edwards asked whether agencies can still select offshore resources under current practice; presenters said agencies can, and today the state raises concerns and asks agencies to document mitigation steps. Woods said the policy under development would provide clearer restrictions and an exception process rather than leaving decisions fully to contracting officers.

Ending: The committee was told the CIO’s office will continue developing a policy, informed by peer states, that clarifies when offshore coding will be prohibited, when it may be allowed under strict controls and how agencies should document and get approval for exceptions.