New points of view on vulnerability management

2024-07-26 10:27:00

This morning on my way to work I listened to the latest episode of Open Source Security podcast. Their topic was very relevant to a past-intern Jana's master's research and to my current intern Cynthia's software project. 

Specifically, episode 438: CISA's bad OSS advice, vs the White House's good advice 

They made some very good points speaking against our team's ideas of doing risk analysis on open source dependencies. I really like it when smart people provide counterpoints to my own thoughts. 

My teams and interns followed a classical approach, where we discern a number of key factors and metrics to determine whether a software dependency is "trustworthy".

I still like that we did these projects, because they can provide insight into our risk exposure. But I agree with the podcast's presenters that such a tool doesn't provide a solution to the problem.  

They pointed to CISA's recent document about this very same problem, which they dubbed unhelpful. And they referred to Mitre's Hipcheck, which is another software solution for risk assessment on open source dependencies. 

It all sounds like great materials to read into! It might even make for some interesting conclusions and counterpoints for our current intern's final report.


kilala.nl tags: ,

View or add comments (curr. 0)