Keynote: Keep Calm and Keep Coding: How To Not Panic When Big CVEs Drop - Brandon Lum, Google

preview_player
Показать описание

Keynote: Keep Calm and Keep Coding: How To Not Panic When Big CVEs Drop - Brandon Lum, OSS Security Software Engineer, Google

When a new critical vulnerability is released or announced, chaos often ensues. There is a rush towards handling the incident - Are we affected? What risk are we exposed to? Which systems need patching/mitigation? A large frenzy ensues because organizations do not have good observability into their software supply chain and inventory. I will share about the value of taking stock of one’s software inventory and how US Whitehouse EO 14028 has catapulted progress in this area. We will then see how in certain cases like the recent CURL CVE, that preparation can be done prior to CVE release, resulting in a more organized incident response with technologies like SBOMs and GUAC.
Рекомендации по теме