How to Keep Good Software from Behaving Badly

No ratings

Presented at SeattleCISOExecutiveSummitQ2 2019 by

As security teams mature, attackers are adapting their tradecraft to avoid detection. The most alarming shift, has been an increasing number of high-profile attacks on the software supply chain. While supplier risk management has matured, and is now part of the NIST Cybersecurity Framework, security best practices around the software supply chain remain more elusive. This gap provides a new and vulnerable target for attackers. In this presentation, David Damato, using his past experience leading investigations at Mandiant and more recent journey building a security engineering team at Tanium, will examine the following:Emergence of software supply chain attacks and examples of associated high profile breachesCommon challenges preventing organizations from securing the software supply chainPractical approaches any enterprise, using or developing software, can implement to mitigate such risks