InfoTechTarget and Informa Tech's Digital Businesses Combine.

Together, we power an unparalleled network of 220+ online properties covering 10,000+ granular topics, serving an audience of 50+ million professionals with original, objective content from trusted sources. We help you gain critical insights and make more informed decisions across your business priorities.

The Cloud Vulnerability Journey - It’s Rocky Terrain

Presented by

Josh Bressers, VP of Security, Anchore

About this talk

How can we connect the dots between all the vulnerability tools and standards to reduce our risk? There are now a number of tools, standards, and compliance that affect vulnerability management in the cloud. Let's identify how everything is related and how technologies such as vulnerability scanners build on top of SBOM and GSD to meet compliance standards. We now have tools that didn’t exist in the past to help on the vulnerability journey. We are seeing vulnerability guidance as compliance standards, executive orders, frameworks, and more. We also have a lot of new tools and projects to help meet this guidance. Software Bill of Materials (SBOM), Global Security Database (GSD), vulnerability scanners, and open source security metrics. Vulnerabilities are everywhere, especially in open source, there’s no escaping them. Just as open source empowered the cloud, it created a new vulnerability management problem space. Regulation and compliance are pointing at needing to treat vulnerabilities as a part of our risk management programs instead of something we mostly ignore. Just like risk, we will never have zero vulnerabilities, so how can we gain some understanding and control over our vulnerabilities? Vulnerability risk management isn’t a destination, it’s a journey.
Cloud Security Alliance: CloudBytes

Cloud Security Alliance: CloudBytes

80687 subscribers1017 talks
Educational series on cloud computing, security and privacy.
CSA CloudBytes was launched as a webinar series to help us educate the industry on all matters related to the cloud. Our channel is designed to inform our audience about trending topics, new technologies, and latest research. Learn more at cloudsecurityalliance.org. Join the Cloud Security Alliance on LinkedIn and follow us on twitter: @cloudsa
Related topics