By Alex Maestretti Description: We held a session to discuss the unique challenges of conducting incident response in the public cloud. We had a great mix of attendees at the P2P session on Incident Response in the public cloud, including practitioners from cloud native companies as well as those from mature organizations just starting to move out of the datacenter. We started the conversation with some war stories on incidents that the audience had worked, and the discussion highlighted several common needs, managing multiple accounts, conducting forensics in an ephemeral hosted environment, …
from Incident Response in the Public Cloud
Showing posts with label RSAC Contributor. Show all posts
Showing posts with label RSAC Contributor. Show all posts
Friday, April 21, 2017
Wednesday, April 19, 2017
Wearables: Security of Things
By Marc Bown In this session, we discussed wearable security, taking into account considerations and constraints unique to wearables and IoT devices. In this session, we used Fitbit’s architecture and experience to frame a discussion around wearable security challenges and best practices. We explored threats that wearable devices face and considered how the unique constraints of wearable devices affect the ability to address those threats. The discussion quickly centered around two basic security controls that IoT devices such as wearable fitness trackers require: encryption and updatability. …
from Wearables: Security of Things
from Wearables: Security of Things
Wednesday, April 12, 2017
Metric Madness: Measuring Success
By Tyler Reguly Metrics for Managing and Understanding Patch Fatigue was ultimately a conversation on how businesses can measure success in their Vulnerability and Patch Management strategies. This year, at RSAC 2017, I hosted a Peer-2-Peer session on Metrics for Managing and Understanding Patch Fatigue. I saw this as an extension of my RSAC 2015 P2P on vulnerability and risk scoring. In 2015, I had a clear vision for the conversation and watched as it moved in a completely different direction. This led to a very interesting conversation but also helped me set my expectations for this year’s…
from Metric Madness: Measuring Success
from Metric Madness: Measuring Success
Friday, April 7, 2017
Implementing SecDevOps in Regulated Industries
Striking the Proper Balance When Dealing with the Inevitable Move to DevOps & Meeting Regulatory and Compliance Requirements By Dan Cornell In addition to my RSAC-TV presentation on Effective Application Security Testing for DevOps, I had the opportunity to run a Peer2Peer session at RSAC 2017 on Implementing SecDevOps in Regulated Industries. I proposed this session topic because, although there is a lot of public information about how organizations are managing their transition to DevOps, most of it relates to organizations that aren’t under heavy regulatory burdens. The information that has…
from Implementing SecDevOps in Regulated Industries
from Implementing SecDevOps in Regulated Industries
Wednesday, April 5, 2017
Peers Discuss Architectural Threat Analysis
By David Graves Architectural threat analysis combines strong architecture specification with threat analysis, enabling early discovery of risks and discussion of alternatives. Twenty five security professionals gathered in a lively peer to peer session at RSA Conference 2017 to discuss how cross-organizational teams can collaborate to produce and analyze architecture specifications to drive secure application development. We agreed that strong architectural specifications empower threat analysis, but had differing experiences in putting the concept into practice. As our discussion progressed, …
from Peers Discuss Architectural Threat Analysis
from Peers Discuss Architectural Threat Analysis
Tuesday, March 28, 2017
Lessons from Managing Your Open Source
By Joshua Bressers During the RSA Conference, I hosted a Peer 2 Peer on how to manage your open source. The purpose of the session was to have a discussion about how the participants were securely managing the open source their organizations were using. It’s no secret these days that nearly every organization is using open source to solve their challenges. Everything from containers running infrastructure to developers leveraging existing code in applications to add complex features quickly. When we look at this from the security perspective though it creates some questions we have to ask. …
from Lessons from Managing Your Open Source
from Lessons from Managing Your Open Source
Monday, September 5, 2016
What’s a Trusted Technology Provider and How Do I Know One When I See One?
By Robert Martin, Sr. Principal Engineer, MITRE, MITRE On Tuesday March 1, as part of the What’s a Trusted Technology Provider and How Do I Know One When I See One? Peer2Peer session at RSA Conference 2016, about 30 people from around the world in industry, government, and academia, met and discussed the various aspects, challenges, and opportunities of finding and recognizing trustworthy suppliers. As the facilitator, I gave opening remarks about the topic and summarized my background and experience. A quick “around-the-room” introduction from by participants followed. Having never…
from What’s a Trusted Technology Provider and How Do I Know One When I See One?
from What’s a Trusted Technology Provider and How Do I Know One When I See One?
Subscribe to:
Posts (Atom)