
Sign up to save your podcasts
Or


Software vulnerability coordination at the CERT Coordination Center (CERT/CC) has traditionally relied on a hub-and-spoke model, with reports submitted to analysts at the CERT/CC analysts who would then work with contact affected vendors. To scale communications and increase the level of collaboration between vulnerability reporters, coordinators, and software vendors, the CERT/CC team has created a web-based platform for software vulnerability reporting and coordination called the Vulnerability Information and Coordination Environment (VINCE). In this SEI Podcast, Emily Sarneso, the architect of VINCE, and Art Manion, technical manager of the Vulnerability Analysis Team in the SEI's CERT Division, discuss the rollout of VINCE, how to use it, and future work in vulnerability coordination.
By Members of Technical Staff at the Software Engineering Institute4.5
1818 ratings
Software vulnerability coordination at the CERT Coordination Center (CERT/CC) has traditionally relied on a hub-and-spoke model, with reports submitted to analysts at the CERT/CC analysts who would then work with contact affected vendors. To scale communications and increase the level of collaboration between vulnerability reporters, coordinators, and software vendors, the CERT/CC team has created a web-based platform for software vulnerability reporting and coordination called the Vulnerability Information and Coordination Environment (VINCE). In this SEI Podcast, Emily Sarneso, the architect of VINCE, and Art Manion, technical manager of the Vulnerability Analysis Team in the SEI's CERT Division, discuss the rollout of VINCE, how to use it, and future work in vulnerability coordination.

32,246 Listeners

273 Listeners

26,380 Listeners

1,105 Listeners

626 Listeners

371 Listeners

651 Listeners

44 Listeners

317 Listeners

8,077 Listeners

73 Listeners

0 Listeners

0 Listeners

6,097 Listeners

1,348 Listeners

139 Listeners

16,525 Listeners