Allan is @allanfriedman on bsky & infosec.exchange

15.3K posts

Allan is @allanfriedman on bsky & infosec.exchange banner
Allan is @allanfriedman on bsky & infosec.exchange

Allan is @allanfriedman on bsky & infosec.exchange

@allanfriedman

#SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.

Katılım Haziran 2009
1.9K Takip Edilen6.6K Takipçiler
Allan is @allanfriedman on bsky & infosec.exchange retweetledi
Mohammad-Ali A'RÂBI
Mohammad-Ali A'RÂBI@MohammadAliEN·
Did you know @Docker has an integration for SBOM generation? $ docker sbom gitweekly/git-weekly On Docker Engine you can install it manually. github.com/docker/sbom-cl…
Freiburg im Breisgau, Germany 🇩🇪 English
0
6
16
6.9K
Ravi Nayyar
Ravi Nayyar@ravirockks·
The far more learned than I have done excellent pieces on CrowdStrike. In my vanity, I have composed three. Each exploring one of the three limbs of how this is the case study my PhD has been waiting for. Here's the first one: what happened and why. atechnolegalupdate.medium.com/crowdstrikes-c…
English
2
2
9
1.8K
Allan is @allanfriedman on bsky & infosec.exchange retweetledi
Viktor Petersson
Viktor Petersson@vpetersson·
Just released an exciting episode of "Nerding Out with Viktor" featuring @allanfriedman from @CISAgov! We dive into Software Bill of Materials (SBOMs) and their crucial role in cybersecurity. Don't miss this deep dive into the future of secure software! Catch the full episode on your favorite podcasting platform here: vpetersson.com/podcast/S01E16…
English
1
1
3
326
Dave Aitel
Dave Aitel@daveaitel·
@ericgeller Most of what it takes to make the LLM good at this has nothing to do with the llm itself but is all about the tools around the llm...
English
1
0
2
160
Allan is @allanfriedman on bsky & infosec.exchange retweetledi
Eric Geller
Eric Geller@ericgeller·
DHS says CISA’s test of AI vulnerability detection methods (required by Biden’s AI EO) determined that “the best use of AI for vulnerability detection currently lies in supplementing and enhancing, as opposed to replacing, existing tools.” dhs.gov/news/2024/07/2…
Eric Geller tweet media
English
1
20
43
13.3K
Eracent
Eracent@eracent·
Members of Eracent's Board of Directors and leadership team visited a hectic Washington D.C. on July 24 to meet with members of the House Homeland Security Committee. We discussed governing cyber tools, processes and people together to ensure effective protection. #SBOM #cyber
Eracent tweet media
English
1
0
2
36
Allan is @allanfriedman on bsky & infosec.exchange
Solid write up of what a maturing organization should think through for SBOM processes, from whichever vendor or tools you choose.
Sonatype@sonatype

🔍 Just as the food industry ensures ingredient safety, the #software industry now requires the same level of oversight and transparency. Dive into our latest blog to learn more about validating, implementing, integrating, and monitoring SBOMs. bit.ly/3WnK1iE #SBOM #SCA

English
0
0
1
421
Allan is @allanfriedman on bsky & infosec.exchange retweetledi
Cybersecurity and Infrastructure Security Agency
The updated Software Bill of Materials (SBOM) Frequently Asked Questions (FAQ) provides information on the benefits of SBOM, common misconceptions and concerns, creation of an SBOM, distributing and sharing an SBOM, and role specific guidance. go.dhs.gov/37S
Cybersecurity and Infrastructure Security Agency tweet media
English
2
16
29
4.5K
Allan is @allanfriedman on bsky & infosec.exchange
Some good points on the economics there. Not sure I agree with the conclusion, but more people (esp in positions like mine and my agency's) should grapple with this essay.
English
3
1
8
2.3K