Showing posts with label RSAC Contributor. Show all posts
Showing posts with label RSAC Contributor. Show all posts

Friday, April 21, 2017

Incident Response in the Public Cloud

By Alex Maestretti Description: We held a session to discuss the unique challenges of conducting incident response in the public cloud. We had a great mix of attendees at the P2P session on Incident Response in the public cloud, including practitioners from cloud native companies as well as those from mature organizations just starting to move out of the datacenter. We started the conversation with some war stories on incidents that the audience had worked, and the discussion highlighted several common needs, managing multiple accounts, conducting forensics in an ephemeral hosted environment, …

from Incident Response in the Public Cloud

Wednesday, April 19, 2017

Wearables: Security of Things

By Marc Bown In this session, we discussed wearable security, taking into account considerations and constraints unique to wearables and IoT devices. In this session, we used Fitbit’s architecture and experience to frame a discussion around wearable security challenges and best practices. We explored threats that wearable devices face and considered how the unique constraints of wearable devices affect the ability to address those threats. The discussion quickly centered around two basic security controls that IoT devices such as wearable fitness trackers require: encryption and updatability. …

from Wearables: Security of Things

Wednesday, April 12, 2017

Metric Madness: Measuring Success

By Tyler Reguly Metrics for Managing and Understanding Patch Fatigue was ultimately a conversation on how businesses can measure success in their Vulnerability and Patch Management strategies. This year, at RSAC 2017, I hosted a Peer-2-Peer session on Metrics for Managing and Understanding Patch Fatigue. I saw this as an extension of my RSAC 2015 P2P on vulnerability and risk scoring. In 2015, I had a clear vision for the conversation and watched as it moved in a completely different direction. This led to a very interesting conversation but also helped me set my expectations for this year’s…

from Metric Madness: Measuring Success

Friday, April 7, 2017

Implementing SecDevOps in Regulated Industries

Striking the Proper Balance When Dealing with the Inevitable Move to DevOps & Meeting Regulatory and Compliance Requirements By Dan Cornell In addition to my RSAC-TV presentation on Effective Application Security Testing for DevOps, I had the opportunity to run a Peer2Peer session at RSAC 2017 on Implementing SecDevOps in Regulated Industries. I proposed this session topic because, although there is a lot of public information about how organizations are managing their transition to DevOps, most of it relates to organizations that aren’t under heavy regulatory burdens. The information that has…

from Implementing SecDevOps in Regulated Industries

Wednesday, April 5, 2017

Peers Discuss Architectural Threat Analysis

By David Graves Architectural threat analysis combines strong architecture specification with threat analysis, enabling early discovery of risks and discussion of alternatives. Twenty five security professionals gathered in a lively peer to peer session at RSA Conference 2017 to discuss how cross-organizational teams can collaborate to produce and analyze architecture specifications to drive secure application development. We agreed that strong architectural specifications empower threat analysis, but had differing experiences in putting the concept into practice. As our discussion progressed, …

from Peers Discuss Architectural Threat Analysis

Tuesday, March 28, 2017

Lessons from Managing Your Open Source

By Joshua Bressers During the RSA Conference, I hosted a Peer 2 Peer on how to manage your open source. The purpose of the session was to have a discussion about how the participants were securely managing the open source their organizations were using. It’s no secret these days that nearly every organization is using open source to solve their challenges. Everything from containers running infrastructure to developers leveraging existing code in applications to add complex features quickly. When we look at this from the security perspective though it creates some questions we have to ask. …

from Lessons from Managing Your Open Source

Monday, September 5, 2016

What’s a Trusted Technology Provider and How Do I Know One When I See One?

By Robert Martin, Sr. Principal Engineer, MITRE, MITRE On Tuesday March 1, as part of the What’s a Trusted Technology Provider and How Do I Know One When I See One? Peer2Peer session at RSA Conference 2016, about 30 people from around the world in industry, government, and academia, met and discussed the various aspects, challenges, and opportunities of finding and recognizing trustworthy suppliers. As the facilitator, I gave opening remarks about the topic and summarized my background and experience. A quick “around-the-room” introduction from by participants followed. Having never…

from What’s a Trusted Technology Provider and How Do I Know One When I See One?