Chris Hughes

896 posts

Chris Hughes banner
Chris Hughes

Chris Hughes

@ResilientCyber

Securing Agentic AI @ Zenity | Founder @ Resilient Cyber | 3x Author | Veteran | Advisor

Katılım Mayıs 2020
159 Takip Edilen447 Takipçiler
Chris Hughes
Chris Hughes@ResilientCyber·
@stevespringett Yeah that seems like a broad interpretation that overlooks the reality that there’s no contractual relationship and most FOSS is provided as-is, and they owe the consumers nothing, including an SBOM.
English
0
0
0
35
Chris Hughes
Chris Hughes@ResilientCyber·
Public Service Announcement (PSA). Free and Open Source Software (FOSS) contributors/maintainers are not your suppliers. That is all.
English
1
3
15
1.8K
Chris Hughes
Chris Hughes@ResilientCyber·
“It’s important to influence designers of future computers and software so that security controls can be installed before the fact and as an integral part of the system”
English
1
0
1
482
Dan Lorenc
Dan Lorenc@lorenc_dan·
if you’re not rolling your own compiler I don’t trust you compilers have to be one of the most easy things to implement and they're such a core component to any service. Own your compiler.
English
60
52
989
225.6K
William Toll
William Toll@utollwi·
The Elusive Built-in not Bolted-on A look at CISA's "Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default" publication via ⁦@ResilientCyber
William Toll tweet media
English
1
1
1
480
Chris Hughes
Chris Hughes@ResilientCyber·
As an industry we’re best-practices rich and implementation poor.
English
0
3
4
1.6K
Dan Lorenc
Dan Lorenc@lorenc_dan·
When you first become a CISO you must become one of the following: LinkedIn CISO, FedRAMP CISO, VC CISO, "cool" CISO, politician CISO, RSA CISO, prepper CISO. I don't make the rules.
English
2
0
24
0
Dan Lorenc
Dan Lorenc@lorenc_dan·
A prospective customer just asked us for an SBOM as part of vendor diligence today for the first time ever. I bet somewhere, @allanfriedman shed a single tear.
English
4
3
68
0
Chris Hughes
Chris Hughes@ResilientCyber·
Excellent article discussing the value and shortfalls of SBOM’s for software supply chain security and how coupling SBOM with SLSA helps fill some gaps. It touches on: - Responding to build tampering attacks such as Solarwinds an…lnkd.in/g95rje8z lnkd.in/gd3wz-ZJ
English
0
3
6
0
Chris Hughes
Chris Hughes@ResilientCyber·
Awesome article comparing Falco and GuardDuty for Amazon Web Services (AWS) EKS Threat Detection by two of my colleagues Dustin Whited and Dakota Riley They discuss: - Kubernetes adoption - Shared Responsibility Model in the con…lnkd.in/gXne_NKX lnkd.in/gvZAFiav
English
0
2
1
0
Chris Hughes
Chris Hughes@ResilientCyber·
About a month ago I had the chance to join NDIA New England to speak on a panel titled "Zero Trusts Given" with Dave Lago, Patrick Perry and moderator Ryan Heidorn The recording for our talk, which starts at the 1 hour 45 minute mark, along with the rest…lnkd.in/gkBNtyW2
English
0
0
0
0
Chris Hughes
Chris Hughes@ResilientCyber·
Yes, another Software Supply Chain Security post today, no I'm not sorry. -- "The Office of Management and Budget is preparing to release new requirements around software supply chain and cybersecurity, according to a top federal…lnkd.in/gBb4_3qb lnkd.in/gQT8DksU
English
1
5
9
0
Chris Hughes
Chris Hughes@ResilientCyber·
I'm a big fan of excellent writing and articles and War on the Rocks puts out some great ones. That's why I was excited to see them publish an article on the Open Source Software (OSS) and Software Supply Chain challenges, and it…lnkd.in/gyyRG9dR lnkd.in/ghGA_RjW
English
0
0
4
0
Chris Hughes
Chris Hughes@ResilientCyber·
National Institute of Standards and Technology (NIST) has just released the final version of 800-161 r1 "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations". This guidance comes at a critical time, as the software supply c…lnkd.in/gYd3WTMN
English
0
5
8
0
Chris Hughes
Chris Hughes@ResilientCyber·
It’s a day of the year where I have to admit to my IT/Cyber peers that I’ve never seen Star Wars I’m sorry to let you all down. #cyber #starwars
English
0
0
0
0