ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

CSAF - the Magic Potion for Vulnerability Handling in Industrial Environments

Автор: FIRST

Загружено: 2022-08-19

Просмотров: 677

Описание: CSAF - the Magic Potion for Vulnerability Handling in Industrial Environments
Speakers: Tobias Limmer (Siemens, DE), Thomas Pröll (Siemens ProductCERT, DE)

Being involved in the field of security since 20 years ago, Tobi has been focusing on the industrial side of IT infrastructures for over 10 years now. Starting with vulnerability handling in Siemens ProductCERT, he was very involved into the automation of security tests. Now one of his research areas is tool-based vulnerability management & risk-based mitigation decisions. And he likes French comics.

Tom is working for Siemens in product security since 15 years. After five years of penetration testing he changed sides and is leading the incident handling and vulnerability response team for Siemens ProductCERT.

----

Vulnerability management for operators of segmented networks such as industrial environments and software suppliers still largely relies on manual processes. This results in high efforts and has tremendous impact on mitigative actions such as patching.Siemens has ramped up its vulnerability handling efforts in the last decade which resulted in publishing over 250 CVEs in 150 advisories in 2021. This amount of information can hardly be handled in the manual way for even moderately complex environments.By supporting the Common Security Advisory Format (CSAF), standardized by OASIS end of 2021, Siemens helps automatable vulnerability management in industrial environments, our Gallic villages.This talk will give an overview of the new CSAF 2.0 release and our experience implementing it. We need a community to support this effort and to improve the situation of vulnerability management, both on the side of publishing vendors and consuming operators. Especially tools are needed that support and automate this process. We will sketch a possible way forward for the whole community, also including SBOMs and VEX in the discussion.

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
CSAF - the Magic Potion for Vulnerability Handling in Industrial Environments

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

CSIRT and SOC Modernization Practices

CSIRT and SOC Modernization Practices

FIRST SIG Updates

FIRST SIG Updates

Did AI Cross the Line? The Anthropic Controversy Explained

Did AI Cross the Line? The Anthropic Controversy Explained

CSAF/VEX: Improved Security Data

CSAF/VEX: Improved Security Data

Secure Supply Chain through Automation - with CSAF, VEX and SBOM

Secure Supply Chain through Automation - with CSAF, VEX and SBOM

Koen Vossen - Ingestify: Rethinking Ingestion for Complex Data - PySport X PyData Eindhoven 2025

Koen Vossen - Ingestify: Rethinking Ingestion for Complex Data - PySport X PyData Eindhoven 2025

4 Hours Chopin for Studying, Concentration & Relaxation

4 Hours Chopin for Studying, Concentration & Relaxation

Kubernetes — Простым Языком на Понятном Примере

Kubernetes — Простым Языком на Понятном Примере

КАК УСТРОЕН TCP/IP?

КАК УСТРОЕН TCP/IP?

Your Phone is Not Your Phone: A Dive Into SMS PVA Fraud

Your Phone is Not Your Phone: A Dive Into SMS PVA Fraud

Эксперт по кибербезопасности о ваших паролях, вирусах и кибератаках

Эксперт по кибербезопасности о ваших паролях, вирусах и кибератаках

Градиентный спуск, как обучаются нейросети | Глава 2, Глубинное обучение

Градиентный спуск, как обучаются нейросети | Глава 2, Глубинное обучение

CSAF-VEX Demo by CISA: Enhancing Cyber Resilience

CSAF-VEX Demo by CISA: Enhancing Cyber Resilience

Для Чего РЕАЛЬНО Нужен был ГОРБ Boeing 747?

Для Чего РЕАЛЬНО Нужен был ГОРБ Boeing 747?

What's New in CSAF v2.1: Key Updates Explained

What's New in CSAF v2.1: Key Updates Explained

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Friday Keynote Address - Network Security is a Team Sport, so How Do We Set and Manage the Team

Friday Keynote Address - Network Security is a Team Sport, so How Do We Set and Manage the Team

Using CSAF to Respond to Supply Chain Vulnerabilities at Large Scale

Using CSAF to Respond to Supply Chain Vulnerabilities at Large Scale

Понимание GD&T

Понимание GD&T

Как Сделать Настольный ЭЛЕКТРОЭРОЗИОННЫЙ Станок?

Как Сделать Настольный ЭЛЕКТРОЭРОЗИОННЫЙ Станок?

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]