Vulnerability Management; Let's talk Vulnerability Chaining

No ratings

Presented at BSidesNova 2020 by

Vulnerability management and remediation is a constant issue for many federal and private sector organizations. With the sheer volume of patches released daily, in combination with the amount of software organizations are using to support their mission, it is impossible to keep up. I will help to wade through the mess that is vulnerability management, while providing tangible solutions to implement in the organization. One topic I will touch on (that many managers or IT Security professionals may not be accounting for) are possibility of chained vulnerabilities, and why it is so important to be aware of this when prioritizing vulnerability remediation.This presentation will give the attendee a range of options to help solve vulnerability management issues; such as prioritization of vulnerabilities and systems, the consolidation / removal of old and antiquated software, as well as resources and tools to aid in this process. With solutions in hand to resolve common vulnerability management issues (EOL software, virtualization, Cloud as a Solution, hardware refreshes, old COTS products, and software inventory consolidation), attendees will walk away with actionable items to help improve the security posture of their networks and organizations.At the end of the session, attendees will be able to take tasking and project ideas back to their organization to resolve old vulnerabilities, improve security scans, and create dynamic vulnerability reporting for executive management. Individuals who attend will also be able to comprehend how medium and low vulnerabilities can be used in combination to create a more critical attack, and how those vulnerabilities need to be remediated too. Along with the other presentation objectives, attendees will be able to identify how vulnerabilities can be prioritized to reduce risk, improve security posture, and consolidate software product.