This episode is a special cybersecurity awareness month podcast where we discuss the 15-year history and future of the CWE/CAPEC program. Interviewees include:
-Bob Martin, Senior Principal Software and Supply Chain Assurance Engineer at MITRE
-Joe Jarzombek, Director of Government and Critical Infrastructure Programs at Synopsis
-Chris Eng, Chief Research Officer at Veracode
-Chris Levendis, CWE/CAPEC Project Leader at MITRE
-Drew Buttner, Software Assurance Capability Area Lead at MITRE
References from this episode:
IS0/IEC 5055:2021 - Information technology; Software measurement; Software quality measurement; Automated source code quality measures - https://www.iso.org/standard/80623.html
CWE-1340 - https://cwe.mitre.org/data/definitions/1340.html
SBOM - https://www.ntia.gov/SBOM