We Speak CVE

Enhancing CVE Records as an Authorized Data Publisher


Listen Later

Kent Landfield of McAfee and Art Manion of CERT/CC discuss how the CVE Program’s upcoming release of JSON 5.0 will allow for additional and related information to be added to CVE Records after they have been published by CVE Numbering Authorities (CNAs). These additions — such as risk scores, affected product lists, versions, references, translations, etc. — will be made by “Authorized Data Publishers (ADPs),” which will be organizations authorized within the CVE Program to enrich the records. Also discussed are the benefits of enriched CVE Records to downstream users and the overall vulnerability management community, the use of Stakeholder-specific Vulnerability Categorization (SSVC), and plans and expectations for the upcoming ADP pilot.

...more
View all episodesView all episodes
Download on the App Store

We Speak CVEBy CVE Program

  • 5
  • 5
  • 5
  • 5
  • 5

5

3 ratings


More shows like We Speak CVE

View all
Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,737 Listeners

The NPR Politics Podcast by NPR

The NPR Politics Podcast

25,874 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,005 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

497 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,083 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

Hard Fork by The New York Times

Hard Fork

5,532 Listeners