Saturday, October 6, 2018

NTIA on Software Component Transparency

The National Telecommunications and Information Administration's (NTIA) first meeting on Software Component Transparency was held on July 19, 2018. From NTIA:
NTIA’s next cybersecurity multistakeholder process will focus on Software Component Transparency. Participants will explore how manufacturers and vendors can communicate useful and actionable information about the third-party software components that comprise modern software and IoT devices, and how this data can be used by enterprises to foster better security decisions and practices.
The next meeting is scheduled for November 6, 2018.

NTIA posted the video and transcripts from their July 19, 2018 meeting as well as the slides from the perspective sharing presentations. The presenters included members from CERT/CC, Oracle Security Alerts Group, Siemens Healthineers, CA Veracode, PTC, and New York Presbyterian.

Each presenter gave an 8-minute talk. The presentation from Josh Corman, the co-founder of the security group I Am The Calvary and the CSO of PTC, starts at 44:30. Here are his presentation slides. He discusses the Software Bill of Materials (SBOM) for medical devices.



Transcript (click to expand)

• Part 1

• Part 2

• Part 3

• Part 4

• Part 5

















No comments:

Post a Comment