Тёмный

SBOMs - The Missing Link 

FIRST
Подписаться 4 тыс.
Просмотров 163
50% 1

Cassie Crossley (Schneider Electric, US)
Cassie Crossley, Vice President, Supply Chain Security in the global Cybersecurity & Product Security Office at Schneider Electric, is an experienced cybersecurity technology executive in Information Technology and Product Development and author of Software Supply Chain Security: Securing the End‐to‐End Supply Chain for Software, Firmware, and Hardware. She has many years of business and technical leadership experience in supply chain security, cybersecurity, product/application security, software/firmware development, program management, and data privacy.
Cassie has designed frameworks and operating models for end‐to‐end security in software development lifecycles, third party risk management, cybersecurity governance, and cybersecurity initiatives. She is a member of the CISA SBOM working groups and presents frequently on the topic of SBOMs and Supply Chain Security.
Cassie has held previous positions at Ceridian, Hewlett‐Packard, McAfee, Lotus, and IBM. She has an M.B.A. from California State University, Fresno, and her Bachelor of Science degree in Technical and Professional Communication with a specialization in Computer Science.
---
There is some debate as to how SBOMs can enhance vulnerability management practices, and some believe that collecting SBOMs from internal teams or suppliers is too difficult and time-consuming. Learn how Schneider Electric has collected thousands of our product SBOMs and how we are leveraging the SBOMs as part of our corporate product CERT to quickly analyze and focus our attention when time is of importance. This presentation describes how we modified our policies and processes to collect, generate, and store thousands of SBOMs. You will hear how we have leveraged SBOMs during the Log4j and OpenSSL vulnerability events. Then we will conclude with key learnings, suggestions, and opportunities for improvement.

Наука

Опубликовано:

 

8 май 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
Этот Пёс Кое-Что Наделал 😳
00:31
APT 101: Understanding Advanced Persistent Threats
41:25
Firmware Supply Chain Security BoF
55:38
Просмотров 71
Product Team Meeting - 2019-07-09
42:43
Просмотров 381 тыс.
Why I Chose Rust Over Zig
33:18
Просмотров 21 тыс.
Battery  low 🔋 🪫
0:10
Просмотров 6 млн
iPhone 15 Pro в реальной жизни
24:07
Просмотров 345 тыс.
iPhone 15 Pro в реальной жизни
24:07
Просмотров 345 тыс.