GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Allan Friedman (allanfriedman@infosec.exchange)

  1. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Friday, 22-Nov-2024 23:50:02 JST Allan Friedman Allan Friedman

    ICYMI: SEI has announced the details for the SBOM Harmonization Plugfest, including 8 targets in different languages.

    More details below, including FAQ and timetable. SBOM submissions due on December 10.

    Video of info session: https://www.youtube.com/watch?v=V4ZRXF8YMzM

    All details: https://resources.sei.cmu.edu/news-events/events/sbom/participate.cfm

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. SBOM Harmonization Plugfest 2024
      The SEI is seeking participants for a project to investigate how various tools generate different software bills of materials (SBOMs) for the same software. ...
    2. No result found on File_thumbnail lookup.
      Participation Instructions for SBOM Harmonization Plugfest 2024
      Hw to participate in the SBOM Harmonization Plugfest 2024
  2. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Friday, 22-Nov-2024 01:21:56 JST Allan Friedman Allan Friedman
    in reply to
    • kurtseifried (he/him)
    • Josh Bressers
    • mkolsek

    @kurtseifried @joshbressers

    definitely tracking RH, etc.

    Is there a better term for what I'm describing for proprietary SW?

    And Kurt - been intrigued by 0patch and other shim solutions since meeting @mkolsek years ago at RSA. Super cool idea. (except it does extreme violence to a lot of assumed trust models...)

    In conversation about 7 months ago from infosec.exchange permalink
  3. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Friday, 22-Nov-2024 00:49:09 JST Allan Friedman Allan Friedman
    in reply to
    • kurtseifried (he/him)
    • Josh Bressers

    @kurtseifried @joshbressers in particular, paid support for commercial software that is no longer supported by the OEM.

    ("support" is another challenge)

    In conversation about 7 months ago from infosec.exchange permalink
  4. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Friday, 22-Nov-2024 00:49:08 JST Allan Friedman Allan Friedman
    in reply to
    • kurtseifried (he/him)
    • Josh Bressers

    @kurtseifried @joshbressers

    building on my RSA talk https://www.rsaconference.com/USA/agenda/session/All%20Good%20Things%20End%20of%20Life%20and%20End%20of%20Support%20in%20Policy%20and%20Practice

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments


  5. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Friday, 22-Nov-2024 00:39:53 JST Allan Friedman Allan Friedman

    Anyone seen any solid research on third party software support? (or even vacuous research?) What do we know about the scale, scope, and focus of the industry? Anyone know any experts? Or even have some experience with vendors?

    In conversation about 7 months ago from infosec.exchange permalink
  6. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Wednesday, 13-Nov-2024 23:31:52 JST Allan Friedman Allan Friedman

    Very exciting news - Microsoft is now publishing automation-friendly security advisories in CSAF format. CSAF allows for more detail and different groupings that just CVEs, and allows orgs to share advisories on security issues that do not have CVEs.

    https://msrc.microsoft.com/blog/2024/11/toward-greater-transparency-publishing-machine-readable-csaf-files/

    In conversation about 7 months ago from infosec.exchange permalink
  7. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Thursday, 19-Sep-2024 04:18:35 JST Allan Friedman Allan Friedman
    • Patrick C Miller :donor:

    “If we need to give up the entire [cyber insurance] business, we are prepared to do so…”

    But the article still describes Munich Re’s drop in cyber insurance market share as “slight” — headlines don’t always paint the whole picture.

    https://www.theinsurer.com/reinsurancemonth/munich-re-willing-to-walk-away-from-business-after-excluding-cyber-war-from-entire-portfolio/

    h/t @patrickcmiller

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: imengine.public.prod.wbm.infomaker.io
      TA invests in cat modelling software firm KatRisk
      from The Insurer
      Global private equity firm TA Associates has invested in KatRisk, a Berkeley, California-based catastrophe modelling software company.
  8. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Tuesday, 27-Jun-2023 22:55:54 JST Allan Friedman Allan Friedman
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller interesting bouncing between the clear statement of immediate threats (ransomware, BEC) and the national security level threats. I’ll have to read the actual report. Thanks for sharing.

    In conversation Tuesday, 27-Jun-2023 22:55:54 JST from infosec.exchange permalink
  9. Embed this notice
    Allan Friedman (allanfriedman@infosec.exchange)'s status on Tuesday, 20-Jun-2023 21:18:21 JST Allan Friedman Allan Friedman
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller counterpoint: large bets without concrete evidence or strategy is, in fact, “hype”

    In conversation Tuesday, 20-Jun-2023 21:18:21 JST from infosec.exchange permalink

User actions

    Allan Friedman

    Allan Friedman

    SBOM Champion. Full service technocrat. Now at @Cisagov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          138373
          Member since
          20 Jun 2023
          Notices
          9
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.