9. The 411 on PSIRTs and the Incident Response Framework
9. The 411 on PSIRTs and the Incident Response Framework

9. The 411 on PSIRTs and the Incident Response Framework

Ngarama

29 min
Knowledge
Play

Description

<p><span style="font-weight: 400;">In this episode of</span> <em><span style="font-weight: 400;">Cyber Security Inside,</span></em> <span style="font-weight: 400;">hosts Tom Garrison and Camille Morhardt talk PSIRTs with Director for Red Hat Product Security, Pete Allor.</span></p> <p> </p> <p><span style="font-weight: 400;">Pete has an impressive history with PSIRT and the convo covers things like:</span></p> <p><span style="font-weight: 400;">•  What a PSIRT is and why you need to have one</span></p> <p><span style="font-weight: 400;">•  The dangers of falling into a technical trap when addressing product vulnerabilities or problems</span></p> <p><span style="font-weight: 400;">•  Evaluating risk and scoring vulnerability</span></p> <p><span style="font-weight: 400;">•  Why incident response requires organization-wide coordination and communication</span></p> <p><span style="font-weight: 400;">•  The Incident Response Services framework</span></p> <p><span style="font-weight: 400;">•  The role transparency plays </span></p> <p><span style="font-weight: 400;">•  And more</span></p> <p> </p> <p><span style="font-weight: 400;">Plus, Pete’s got a book recommendation, Camille’s got a tip for musicians forced to play in the dark, and Tom’s got a trivia question that will get you free drinks, every time. Check it out!</span></p> <p> </p> <p><strong>Here are some key take-aways:</strong></p> <p><span style="font-weight: 400;">•  PSIRT is designed to address vulnerabilities with the company’s own products. If you don’t have a Product Security Incident Response Team, you need one.</span></p> <p><span style="font-weight: 400;">•  Get to know your auditor well and figure out what your risk tolerance is internally. </span></p> <p><span style="font-weight: 400;">•  PSIRT should be proactive, not reactive.</span></p> <p><span style="font-weight: 400;">•  We need to talk vulnerability scoring, so we have a commonality, a base to work from. And we need to talk about severity, as in risk.</span></p> <p><span style="font-weight:

Uploader

josie.shore

josie.shore

9. The 411 on PSIRTs and the Incident Response Framework - Listen Free | WowFM