BSidesRDU 2022 - SBOM + VEX + CSAF = The Future of Vulnerability Management - Panel: Omar Santos, Diane Morris, Josh Dembling, Lisa Bradley, Art Manion
https://bsidesrdu.org/
SBOMs (Software Bills of Materials) sound like a great idea, right? Everyone will know everything that’s in every piece of software from every vendor. Great! But as an IT professional, what do you do with that information? It’s not possible—or desirable—to patch every vulnerability in every piece of code.What you need is an automated way to get information from product vendors about vulnerabilities, filter out the ones that don’t affect your products, and quickly identify what actions you need to take to keep your organization safe. What a future that would be!
Well, the future is now! Vulnerability Exploitability eXchange (VEX) documents formatted using the Common Security Advisory Framework (CSAF) will turn your asset management system into a vulnerability management powerhouse.This panel will bring together two preeminent experts in SBOMs, VEX, and CSAF for a conversation about how these concepts will change vulnerability management.
The panelists are:
Omar Santos, Product Security Incident Response Team, Cisco
Lisa Bradley, Sr. Director, Product and Application Security, Dell
Art Manion, Software Engineering Institute (SEI), Carnegie Mellon University
Josh Dembling, Sr. Director, Product Security Incident Response Team, Intel
The panel will be moderated by Diane Morris, a content manager with Cisco PSIRT. Diane’s team touches every security advisory that Cisco releases, and she wants to learn how SBOM and VEX will change how PSIRT discloses vulnerabilities and how customers consume that information.
Questions that will be addressed by this panel include:
• What will the widespread use of SBOMs mean for defenders?
• How will SBOMs come into play during the next SolarWinds-level event?
• How complicated is the SBOM process for a large company like Cisco?
• What are VEX documents, and how do SBOMs and VEX documents work together?
• Why is there such a strong emphasis on machine readability for VEX?
• How will IT professionals use VEX documents?
• What is CSAF, and how will it influence how we use VEX?
• What will the rise of VEX mean for how companies disclose vulnerability information and how IT professionals use that information?
Theatre
Sat 9:45 am - 10:30 am
--
Omar Santos
Cybersecurity peasant
Omar Santos is a recognized leader in the cybersecurity community. He leads several industry-wide initiatives and standards. Omar is the author of over twenty books and video courses, as well as numerous articles and whitepapers. Omar is a principal engineer of the Cisco Product Security Incident Response Team (PSIRT), where he mentors and leads engineers during the investigation and resolution of cyber security vulnerabilities. Omar is the founding leader of the DEFCON Red Team Village and the founder of BSIDES RDU. He is the chair of the Common Security Advisory Framework (CSAF) technical committee.
--
Diane Morris
Cisco Security Content Manager
Diane has more than 25 years of experience as a journalist, writer, and editor. She has been a content manager with Cisco PSIRT for almost three years and is trying to learn everything she can about how to most effectively communicate security information.
--
Josh Dembling
Intel - Senior Director, Product Security Incident Response Team
Josh Dembling is a Senior Director at Intel Corporation and runs the Intel Product Security Incident Response Team (PSIRT) and Bug Bounty Program. He has led organization transformations while at Intel, IBM and Motorola. Josh specializes in product/business development, product security, vulnerability response management, Bug Bounty programs and security researcher outreach. He is a leader in technology industry groups where he drives collaboration on initiatives that encourage the exchange of ideas on solutions to product security challenges common across the industry. Josh is the co-chair for the FIRST.org PSIRT Special Interest Group. Outside of work Josh can be found taking long walks in the rain, dancing like no one is looking and hunting for unicorns.
--
Lisa Bradley
Sr. Director Product and Application Security @ Dell
Dr. Lisa Bradley is the Senior Director of Product & Application Security at Dell Technologies focusing on Vulnerability Response, Customer Security and Community Enablement. In this role, she oversees Dell's Product Security Incident Response Team (PSIRT), Bug Bounty Program, SBOM, and third-party Dependency Management. She also oversees Dell’s Security Champion Program, Security Training Program, and the Customer Security team where she strives to meet Dell’s customer security needs and build customer trust into the core of product and application security practices. Lisa has 20+ years of Enterprise-class [...]/edited-for-field-length