Vulnerability management lifecycle l.jpg
This presentation is the property of its rightful owner.
Sponsored Links
1 / 11

Vulnerability Management Lifecycle PowerPoint PPT Presentation


  • 64 Views
  • Uploaded on
  • Presentation posted in: General

Vulnerability Management Lifecycle. Panel Discussion. Panelists. Carole Fennelly - Tenable Network Security Chris Wysopal - Veracode Steven Christey - MITRE Bob Martin - MITRE HD Moore - Rapid7 Jonathan Klein - Broadridge Financial Solutions

Download Presentation

Vulnerability Management Lifecycle

An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -

Presentation Transcript


Vulnerability management lifecycle l.jpg

Vulnerability Management Lifecycle

Panel Discussion


Panelists l.jpg

Panelists

Carole Fennelly - Tenable Network Security

Chris Wysopal - Veracode

Steven Christey - MITRE

Bob Martin - MITRE

HD Moore - Rapid7

Jonathan Klein - Broadridge Financial Solutions

Kelly Todd - OSVDB


Overview l.jpg

Overview

  • Vulnerability Discovery

  • Private Vulnerability Sharing

  • Public Disclosure

  • Vulnerability Database Management

  • Vulnerability Monitoring/Testing

  • Remediation


Lifecycle players l.jpg

Lifecycle Players


Vulnerability discovery l.jpg

Vulnerability Discovery

  • Monitoring for Anomalies/ 0-Day

  • Monitoring Local Applications

  • Initial Discovery of Vulnerability

  • Development of Exploit

  • Posting to security lists


Private vulnerability sharing l.jpg

Private Vulnerability Sharing

  • Passing around on underground lists

  • Additional research

  • Expanded impact

  • 0-day exploits

  • “Oops, I broke the Internet…”


Public disclosure l.jpg

Public Disclosure

  • Determine when to disclose

  • Coordination between vendor and researcher

  • What to disclose

  • Public reaction/ working with media

  • FUD


Vulnerability database management l.jpg

Vulnerability Database Management

  • Monitoring of sources

  • Validation

  • Summarization

  • Classification

  • Determine/develop remediation measures


Vulnerability monitoring testing l.jpg

Vulnerability Monitoring/Testing

  • Vulnerabilities discovered during a penetration test

  • Vulnerabilities discovered by security software (IDS, Logs, Scanners)

  • Vulnerabilities discovered from external source


Remediation l.jpg

Remediation

  • Analysis of organizational impact

  • Prioritization

  • Determine/test remediation measures


Questions l.jpg

Questions?

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]


  • Login