Draft of National Source Code Policy, 2025 Published for Public Feedback

Facebook
Twitter
LinkedIn
WhatsApp

Dhaka: The draft of the 'National Source Code Policy, 2025' has been published on the ICT Division's website (ictd.gov.bd), carrying the tagline 'Public Money, Public Code'. This newly proposed policy aims to establish government-funded software as a national resource, ensuring public interest-based ownership, security, transparency, and reusability of software developed with public funds.

According to Bangladesh Sangbad Sangstha, the policy applies to government-developed or adopted software systems, applications, apps, APIs, and digital services funded by the national budget, foreign loans, or development partners under government implementation. It mandates compliance from all ministries, divisions, directorates, and statutory, autonomous, and semi-autonomous entities.

The policy outlines several key provisions, including the preservation of source code, documents, and related components of all government-funded software in a National Source Code Repository. This repository will be managed by the Bangladesh Computer Council under appropriate supervision, ensuring traceability and auditability. The policy prohibits deploying unreliable software in production until the relevant source code is stored in the repository, with instructions to establish an escrow system if necessary.

Organizations are required to adopt a "Reuse First" approach before developing new software, with a provision to mandatorily reuse existing solutions. Authorities must be informed in writing if reusing is not feasible. As a fundamental principle, government-owned source code should generally be considered open source unless exempted under the 'public money, public code' principle.

For cases involving national security, defense, confidentiality, or special circumstances, exemptions from disclosure may be granted, but maintenance through the repository remains mandatory. Exempted systems must provide written justification, registration, and periodic review. The policy includes guidelines for using approved licenses for open source code.

A framework for secure coding guidelines through a Standard Coding Guideline Committee has been proposed, and adherence to an approved CI/CD pipeline in software deployment is mandatory. This includes automated testing, vulnerability scanning, and license verification, along with manual approval before production release.

The repository will operate under 'Role Based Access Control' (RBAC), requiring contributors, maintainers, approvers, or auditors to sign a government-approved NDA before access is granted. Additionally, government software-related datasets must be classified into three categories-Open, Restricted, and Regulated-and registered in the National Data Catalog with necessary metadata.

The draft policy is available for stakeholder feedback on the ICT Division's website. Bangladeshi citizens, both domestic and abroad, experts in the field, university professors, and representatives from relevant government agencies, development partners, industry, and academia are invited to submit their written opinions or recommendations on the draft.

Feedback can be sent via email to [email protected] or by post to the Secretary, Information and Communication Technology Division, ICT Tower (4th Floor), Agargaon, Dhaka.