
CSCP S03EP23 - Chris Hughes - Demystifying Application Security Programs
Escudero
Description
<p></p> <p> </p> <p class="p1">Chris Hughes is a Proven Cloud/Cybersecurity leader with nearly 20 years of experience in the Federal and commercial industries. Chris is an active blogger, passionate about all things cyber and a published author of books like Software Transparency. </p> <p class="p1"> </p> <p>The episode is brought to you by Phoenix Security; get in control of your vulnerabilities from code to cloud with the power of Phoenix. ACT Now on the vulnerabilities that matter most and reduce your exposure to modern attacks. See it for yourself. Go to <a href='https://www.phoenix.security'>https://www.phoenix.security</a> for a free 14-day licence.</p> <p> </p> <p class="p1">1:12 Introductions</p> <p class="p1">4:45 regulation and federal space</p> <p class="p1">6:40 Software supply chain attacks</p> <p class="p1">8:40 SSDF and SBOM</p> <p class="p1">11:06 Software is complex</p> <p class="p1">15:00 Vulnerability to attacks, attacker mindset </p> <p class="p1">17:00 Common supply chain attacks</p> <p class="p1">20:00 Cloud critiques, is cloud secure?</p> <p class="p1">23:00 Business Risk, Quantifications, How to measure everything, </p> <p class="p1">24:00 FAIR and Quantification at scale</p> <p class="p1">25:00 Method to evaluate vulnerability, CISA KEV, EPSS, How to triage</p> <p class="p1">28:00 Why does the software supply chain get attention</p> <p class="p1">30:00 Get connected</p> <p class="p1"> </p> <p class="p1">Chris Huges</p> <p class="p1"> </p> <p class="p1"><a href='https://www.linkedin.com/in/resilientcyber/'>https://www.linkedin.com/in/resilientcyber/</a> </p> <p class="p1"><a href='https://podcasts.apple.com/us/podcast/resilient-cyber/id1555928024'>https://podcasts.apple.com/us/podcast/resilient-cyber/id1555928024</a> </p> <p class="p1"><a href='https://resilientcyber.substack.com/'>https://resilientcyber.substack.com/</a> </p> <p class="p1">FAIR: <a href='https://www.opengroup.org/certifications/openfair'>https://www.opengroup.org/certifications/openfair</a> </p> <p class="p1">Hot to measu