Policy Briefings
These briefing notes help decision-makers place CHERI within wider memory-safety, secure-by-design, procurement, and resilience policy.
Policy discussions about memory safety can become too narrow: rewrite everything, add another mitigation, or wait for the market. CHERI provides an additional route that is particularly relevant to established native code and systems needing fine-grained isolation.
Briefing: memory safety is a portfolio decision
No single intervention covers every system. Memory-safe languages can prevent broad classes of defects in new code. CHERI can enforce memory access in low-level and existing software and help create least-authority compartments. Testing, hardening, process isolation, secure updates, and vulnerability management remain necessary.
Policy action: ask organisations for a measurable memory-safety roadmap that segments code by risk and assigns an appropriate intervention to each segment.
Briefing: adoption needs infrastructure
A processor feature becomes useful only with toolchains, operating systems, libraries, debugging, training, assurance, and available products. Public investment in shared infrastructure can reduce duplicated work and give buyers credible evidence.
Policy action: support open specifications, compliance tests, reproducible platforms, contributions to mainline software projects, skills, test facilities, and evaluation by users with real workloads.
Briefing: procurement should reward outcomes
Technology labels can exclude alternatives without proving security. Requirements should describe the memory-safety coverage, compartment boundaries, lifecycle support, and evidence expected. When a specific CHERI profile is needed for interoperability, state the profile and version.
Policy action: require suppliers to disclose which software is protected, what can bypass capability checks, what authority remains after compromise, and how claims will be maintained.
Briefing: resilience includes failure behaviour
Stopping an invalid access is valuable, but an essential service must also respond safely to the resulting fault. Recovery, availability, logging, and safe degradation belong in the evaluation.
Policy action: fund and procure fault-injection and recovery evidence alongside memory-protection tests.
Preparing a decision briefing
Every briefing should include the audience, decision, current baseline, proposed intervention, alternatives, evidence, limitations, cost range, dependencies, owner, and next review date. Link to primary sources and date every regulatory statement.
The Alliance can help explain CHERI technology and connect policy teams with technical expertise. Regulators and competent authorities remain the source of legal interpretation.
