They’re definitely not seen as an authority in this field. Why would anyone care what recommendation they make?
It's possible that they are acting on the advice of advisors who are authorities in this field.
And so why make one at all?
I expect it's because information and industrial security are components of national security, which is of great concern to them, and those things depend on software.
I'm not surprised to see this, given that state-sponsored electronic attacks are on the rise these days.