We Speak CVE

CNA Onboarding Process Myths Versus Facts


Listen Later

Shannon Sabens of CrowdStrike chats with Dave Morse, program coordination lead for the CVE Program, about the myths and facts of the CVE Numbering Authority (CNA) partner onboarding process.

Truth and facts about the following topics are discussed: duration and complexity of the onboarding process; the fact that there is no fee to participate; ease of incorporating assigning CVE Identifiers (CVE IDs) and publishing CVE Records into an organization’s existing coordinated vulnerability disclosure (CVD) processes; availability of automated tools for CNAs; the CVE JSON Record format and available guidance; role of Roots and Top-Level Roots and how they help CNAs; importance of CNAs determining their own scopes; disclosure policies; the community aspect of being a CNA and the availability of peer support; the value of CNAs participating in one or more CVE Working Groups, especially the CNA Organization of Peers (COOP); and much more!

...more
View all episodesView all episodes
Download on the App Store

We Speak CVEBy CVE Program

  • 5
  • 5
  • 5
  • 5
  • 5

5

3 ratings


More shows like We Speak CVE

View all
Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,548 Listeners

The NPR Politics Podcast by NPR

The NPR Politics Podcast

25,843 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

500 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,049 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

137 Listeners

Hard Fork by The New York Times

Hard Fork

5,524 Listeners