We Speak CVE

The Value of Assigning CVEs


Listen Later

Shannon Sabens of CrowdStrike chats with Madison Oliver of GitHub Security Lab about how and why CVEs are assigned, the value of CVEs in vulnerability management, responsible coordination of vulnerability disclosures, the importance of comprehensiveness in security advisories, and why there is no stigma in a CVE. CVE Numbering Authority (CNA) scopes, disclosure policies, turnaround times, and more are discussed in general, as are GitHub’s specific CNA processes and how it helps open-source projects hosted on GitHub with their CVEs and advisories.

Madison also writes about many of these topics in her blog article, Removing the Stigma of a CVE, on the GitHub Blog.

...more
View all episodesView all episodes
Download on the App Store

We Speak CVEBy CVE Program

  • 5
  • 5
  • 5
  • 5
  • 5

5

2 ratings


More shows like We Speak CVE

View all
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

634 Listeners