2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1
2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1

2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1

Mrs_Marong💞

37 min
News
Play

Description

<p><span style="font-weight: 400;">Introduce Katie (bio) (@k8em0) CEO and Owner, LutaSecurity</span></p> <p><span style="font-weight: 400;">The scope of the VCMM (what is it?)</span></p> <p><span style="font-weight: 400;">VCMM - Vulnerability Coordination Maturity Model </span></p> <p><a href="https://www.lutasecurity.com/vcmm"><span style= "font-weight: 400;">https://www.lutasecurity.com/vcmm</span></a></p> <p><span style="font-weight: 400;">Just covers the internal process? To ready an org for a bug bounty program or to accept vulns from security researchers?</span></p> <p><span style="font-weight: 400;">You mentioned not playing whack-a-mole, when it comes to responding at the beginning of a vuln disclosure program. Is the directing of different categories of bugs one of the things that goes into not having to just wait for the bugs to roll in?</span></p> <p><span style="font-weight: 400;"><br /></span><span style= "font-weight: 400;">Will this work for internal security or red teams as well, or is this more suited to bug bounties?</span></p> <p><span style="font-weight: 400;">What’s the timeline for this process? “We need something for a product launch next week…”</span></p> <p><span style="font-weight: 400;">Stakeholders involved? CISO? Security team? IT? Devs?</span></p> <p><span style="font-weight: 400;">What precipitates the need for this? Maturity? Vuln Disclosure? </span></p> <p><span style="font-weight: 400;">Are the ISO docs required for this to work, or will they assist in an easier outcome?</span></p> <p><span style= "font-weight: 400;">https://blog.rapid7.com/2017/12/19/nist-cyber-framework-revised-to-include-coordinated-vuln-disclosure-processes/</span></p> <p><a href= "https://www.rsaconference.com/industry-topics/video/bug-bounty-programs-arent-enough-for-todays-cyber-threats-katie-moussouris-rsac"> https://www.rsaconference.com/industry-topics/video/bug-bounty-programs-arent-enough-for-todays-cyber-threats-katie-moussouris-rsac</a> </p> <p><span style="font-weight: 400;">10 worst jobs (popsci a

Uploader

holly.cove

holly.cove

2020-036-Katie Moussouris, Vulnerability Coordination Maturity Model, when are you ready for a bug bounty - Part 1 - Listen Free | WowFM