Jake Kouns is the CISO for Risk Based Security that provides vulnerabilities and data breach intelligence. He previously oversaw the operations of the Open Sourced Vulnerability Database (OSVDB.org) and DataLossDB. Kouns has presented at many well-known security conferences, including RSA, Black Hat, DEF CON, DerbyCon, FIRST, CanSecWest, InfoSecWorld, SOURCE and more! Christine Gadsby is the Director of BlackBerry's global Product Security Incident Response Team (SIRT). This highly respected team monitors the security threat landscape and responds rapidly to emerging threats for all of BlackBerry's products and services and those of its subsidiaries and consulting customers. Open source software (OSS) usage is on the rise and also continues to be a major source of risk for companies.ˇ OSS and 3rd party code may be inexpensive to use to build products but it comes with significant liability and maintenance costs.ˇ Even after high profile vulnerabilities in OpenSSL and other critical libraries, tracking and understanding exposure continues to challenge even at the most mature enterprise company. It doesn’t matter if you are a software vendor or not, development and the use of OSS in your organization is most likely significant. It also doesn’t matter if you have been developing software for years or are just getting started, or whether you have one product or one hundred, it can feel to many nearly impossible to keep up with OSS vulnerabilities or more important ensure they are properly mitigated. This presentation looks at the real risk of using OSS and the best way to manage its use within your organization and more specifically the Product Development Lifecycle.ˇ We will examine all the current hype around OSS and separate out what are the real risks, and what organizations should be the most concerned about.ˇ ˇWe explore the true cost of using OSS and review the various factors that can be used to evaluate if a particular product or library should be used at your organization, including analyzing Vulnerability Metrics including Time to Patch. Getting your head wrapped around the issues and the need to improve OSS security is challenging, but then taking action at your organization can feel impossible.ˇ This presentation provides several real world examples that have been successful at Black Berry including: A case study of a single third party library vulnerability across several products will help to show why the result of investigating actual impact against your different products is valuable intelligence. We will provide learnings from your incident response function and why understanding the vulnerabilities in your current software can gain you valuable insight into creating smarter products to avoid maintenance costs. Finally, we will introduce a customized OSS Maturity Model and walk through the stages of maturity for organization developing software with regards to how they prioritize and internalize the risk presented by OSS. This presentation will review the following topics using data and evidence: Part I: -Introduction to the Open Source Software and the security issues (brief) -Vulnerability statistics/review of 2015 and focus on OSS issues/libraries -Legal Liability pressures continue to increase on vendors, examples of recent cases -Concerns with OSS have been constant, but seem to be losing the hype -What are the real issues, what is hype?ˇ What are the biggest risks to consider? -When has OSS gone bad? -When bad code gets submitted or a developer rage quits -License issues are still a critical part of using OSS and can?t be ignored -Understanding actually potential and hidden costs with OSS -Why does the cadence of release cycle matter? -How often are OSS updates released -Too many = way too often to update, huge cost of ownership -Too few = leaves you open to risks and compromise -Need the porridge to be JUST right and prefer secure coding from the beginning -How can you evaluate OSS or determine is there are any potential issues? -How can you tell if an OSS project is mature enough to rely on? -Lack of long term viability of a project -Lack of sponsorship, will the code get abandoned? -Health of the project, # of contributors, # of updates, etc. -Support available?Do they have a contact person/vehicle for security? -Vulnerability Timeline Metrics can help! -How long does it take for researchers to get a response? -How long does it take to provide a patch? Part II: -How do you get executives to buy in? Why is OSS security so important? -A quick view current potential economic risk and the pressure of feature development over writing secure code: Will market force or legal risk prevail first? -Intelligence: Do you know how much OSS you are actually using in your products? -Do you know what versions of those OSS libraries? Are you updating versions or cherry-picking fixes? How do you decide? -How much OSS is actually in a tech vendor - data points on BlackBerry?s OSS usage across its product suite. -Case Study: 1 OSS vuln can affect products differently, blind patching doesn?t make sense. We will look at a of a major OSS vuln across BlackBerry?s product verticals (products affected x cvss score on each x patch timelines) This will paint a picture of the value of investigating OSS vulns and their impact vs. patching timelines -How to evaluate OSS against your products - now that you know how many OSS libs are in your product, what you do about it -Introduce the OSS Maturity Model and how to evaluate OSS -How to use your SIRT and investigation function to determine risk in OSS -How do you handle current and incoming OSS 3rd Party Libs as part of your development lifecycle? -Using Containers to minimize risk -Which OSS project pose the most risk- OSS Blacklist and OSS EOL policy -Learnings and take away from a major tech vendor