In line with our Cybersecurity Strategic Plan and our focus on measuring risk reduction, we are measuring national progress in the adoption of CPGs and associated progress in addressing key risks. Read the details in our latest blog: go.dhs.gov/oCt
Daniel Bardenstein, CTO of @ManifestCyber, joins us on 30 November for the AI Security Summit, hosted by OASIS Open and @Cisco.
@bardenstein will discuss AI transparency: the machine learning bill of materials (#MLBOM aka #AIBOM).
Register (free): aisecuritysummit.org/
ML is growing and this is fertile ground for attackers to exploit the AI supply chain. How do we protect it? Turns out, we can use the same tools as the traditional software (sigstore, SLSA,etc.)
security.googleblog.com/2023…
The @ONCD#DEFCON31 badges were so cool that I had to try to win one by solving the hidden puzzle. With some help and much effort, I finally broke the code 👨💻
Kudos to @RoRoRah and @cybertestpilot for their amazing work, and ONCD for making it all happen.
H/t @DEFCONPolicy
Excited to share that I'll be speaking at @defcon at the @DEFCONPolicy alongside Chris Butera from CISA and Cassie Crossley from Schneider Electric to talk about Secure By Design and the future, tension, and implications for government and software vendors!
Cross-Sector Cybersecurity Performance Goals (CPGs) can help all organizations, regardless of size or industry, prioritize the steps they need to take to mitigate risk of potential threats from sophisticated cyber threat actors. Learn more: cisa.gov/cpg
The team and I can't wait to jump into this forward-thinking, collaborative program to help promote tools that will help #SBOM adoption - and software transparency - globally.
💪 #knowwhatyouremadeof
Lest we forget - solving this problem goes farther than product liability laws (though that would have tremendous impact).
We also need to start teaching CS students how to code securely (e.g. with memory safe languages). 1/
Very excited to hear @CISAJen going after a hard but critical problem: holding software suppliers responsible for insecure code.
washingtonpost.com/politics/…
Imagine we taught all of our home builders how to build homes with the same processes and materials as 20 years ago, then made them learn an entirely new speciality of "how to retroactively make your homes sturdier/greener/etc. after you built them."
it makes no sense.
Very excited to hear @CISAJen going after a hard but critical problem: holding software suppliers responsible for insecure code.
washingtonpost.com/politics/…