Sabitlenmiş Tweet
Allan is @allanfriedman on bsky & infosec.exchange
15.3K posts

Allan is @allanfriedman on bsky & infosec.exchange
@allanfriedman
#SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.
Katılım Haziran 2009
1.9K Takip Edilen6.6K Takipçiler

In case you missed my news elsewhere: This will be my last week at CISA. I’m sad to be leaving a great team, but very excited for some new projects. And don’t worry—I’ll be finding ways to help out with #SBOM!
meritalk.com/articles/cisa-…
English

@ITGRC If you’re looking for more discussions around SBOM and related supply chain issues, happy to chat!
English

SBOM 101: Understand, Implement & Leverage SBOMs for Stronger Security & Risk Management get.anchore.com/sbom101-guide-…
English

Setting up for our first ever SBOM Solutions Showcase! This Denver ballroom will be filled with 24 organizations from around the world to meet your #sbom needs, with many more listed online.
cisa.gov/resources-tool…

English

@ShortArmSAS @LionfishCyber Nice description, and I do like the pushback on the relationship between compliance and security. It can help start things rolling and help prioritize. Thanks @EanMeyer for sharing.
English

We asked #podcast guest Jeremy Miller to tell us all about @LionfishCyber and what makes them awesome in the #CyberSecurity space.
English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

Did you know @Docker has an integration for SBOM generation?
$ docker sbom gitweekly/git-weekly
On Docker Engine you can install it manually.
github.com/docker/sbom-cl…
Freiburg im Breisgau, Germany 🇩🇪 English

@ravirockks @d_jaishankar @arekfurt @ImposeCost @redunley @thegrugq @WatermanReports @VirpratapVS @DanLGolden @emmacs26 Thanks for sharing these. Something to read through while stuck in canceled flight hell on my way home from Black Hat.
English

The far more learned than I have done excellent pieces on CrowdStrike.
In my vanity, I have composed three.
Each exploring one of the three limbs of how this is the case study my PhD has been waiting for.
Here's the first one: what happened and why.
atechnolegalupdate.medium.com/crowdstrikes-c…
English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

Just released an exciting episode of "Nerding Out with Viktor" featuring @allanfriedman from @CISAgov! We dive into Software Bill of Materials (SBOMs) and their crucial role in cybersecurity. Don't miss this deep dive into the future of secure software!
Catch the full episode on your favorite podcasting platform here:
vpetersson.com/podcast/S01E16…
English

@daveaitel @ericgeller and ditto to attack the LLM, yes?
English

@ericgeller Most of what it takes to make the LLM good at this has nothing to do with the llm itself but is all about the tools around the llm...
English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

DHS says CISA’s test of AI vulnerability detection methods (required by Biden’s AI EO) determined that “the best use of AI for vulnerability detection currently lies in supplementing and enhancing, as opposed to replacing, existing tools.” dhs.gov/news/2024/07/2…

English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

If you are curious about what #SBOM, #SLSA and #Scorecard are, and how they inter-relate to strengthen #software #security and #trust, you should read this post from @cpswan 👇 blog.thestateofme.com/2024/07/22/sup…
English

@eracent Next time the team is in DC, drop a line. Happy schedule a meeting and hear from you about SW transparency.
English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

Now that a patch is available, affected grid operators must do the hard work to identify the affected RTUs running vulnerable firmware. This vulnerability highlights a need for a robust ICS SBOM solution.
SecurityWeek@SecurityWeek
Siemens Patches Power Grid Product Flaw Allowing Backdoor Deployment securityweek.com/siemens-patche… #ICS
English

Solid write up of what a maturing organization should think through for SBOM processes, from whichever vendor or tools you choose.
Sonatype@sonatype
🔍 Just as the food industry ensures ingredient safety, the #software industry now requires the same level of oversight and transparency. Dive into our latest blog to learn more about validating, implementing, integrating, and monitoring SBOMs. bit.ly/3WnK1iE #SBOM #SCA
English
Allan is @allanfriedman on bsky & infosec.exchange retweetledi

The updated Software Bill of Materials (SBOM) Frequently Asked Questions (FAQ) provides information on the benefits of SBOM, common misconceptions and concerns, creation of an SBOM, distributing and sharing an SBOM, and role specific guidance. go.dhs.gov/37S

English

Living the “champagne lounge, steerage seats” lifestyle. Looking forward to a great week in Seoul, talking about supply chain security, OSS, and—of course—#SBOM

English





