• Home
  • Resources and Tips
    • Digital Resources
    • Physical Resources
    • Hints and Tips
  • Education
  • IT
  • Learning in the future
  • Schools
  • Students
  • Tech in education
What's hot

What is Pocketalk? The translation tool explained

May 28, 2023

Taking care of yourself during and after exam season – Student Blog

May 28, 2023

Ohio teacher shortage: As schools review vacancies, teachers fill gaps – cleveland.com

May 28, 2023

Assad’s normalization leaves Syrians in Rukban’s camp fearful of the future – Al Jazeera

May 28, 2023
Facebook Twitter Instagram
  • Home
  • Contact us
  • Privacy policy
  • Terms & Conditions
Facebook Twitter Instagram
Teaching Resources Pro
  • Home
  • Resources and Tips
    • Digital Resources
    • Physical Resources
    • Hints and Tips
  • Education

    Can you guess these 10 words from the Scripps Spelling Bee?

    May 28, 2023

    Essay on “Every Brain Needs Music” and “Hi Ren”

    May 26, 2023

    Tips for reducing costs when implementing customer training software

    May 22, 2023

    An economist spent decades saying that money wouldn’t help schools. Now his research suggests otherwise.

    May 20, 2023

    Teacher leadership at the national level

    May 18, 2023
  • IT

    How to Join a Node to a Docker Swarm

    May 28, 2023

    Five key steps when there is a risk of a fraud investigation

    May 26, 2023

    8 VS Code extensions you didn’t know you needed

    May 24, 2023

    Jenkins CI/CD Tool Review | TechRepublic.com

    May 20, 2023

    How to explain data meshes, structures and clouds

    May 16, 2023
  • Learning in the future

    Assad’s normalization leaves Syrians in Rukban’s camp fearful of the future – Al Jazeera

    May 28, 2023

    Montgomery middle schoolers ‘invent the future’ in unique STEM… – The Washington Post

    May 26, 2023

    New book explores the future of leadership learning and… – Business Plus

    May 24, 2023

    Education in crisis: Supporting the future of Syrian children – Syria … – ReliefWeb

    May 22, 2023

    Educational entertainment; The future of education? – The financial express

    May 20, 2023
  • Schools

    Ohio teacher shortage: As schools review vacancies, teachers fill gaps – cleveland.com

    May 28, 2023

    Reed City Public School students receive surprise gift ahead of summer break – Reuters

    May 26, 2023

    Oxford parents push back on proposal to add more guns to… – Reuters

    May 24, 2023

    At least 20 dead in fire at school dormitory in Guyana, officials say: "It’s a major disaster" – CBS News

    May 22, 2023

    UK schools ‘baffled’ by AI and don’t trust tech companies, headteachers say – The Guardian

    May 20, 2023
  • Students

    Taking care of yourself during and after exam season – Student Blog

    May 28, 2023

    Fulfill my mission to attend conferences – SJSU

    May 26, 2023

    Student Loan Repayment Breakdown Guide

    May 24, 2023

    How to Apply for College Recommendation Letters

    May 22, 2023

    Top Questions to Ask Your College or High School Counselor

    May 20, 2023
  • Tech in education

    What is Pocketalk? The translation tool explained

    May 28, 2023

    Improving English learning with technology in the classroom

    May 26, 2023

    Ten Ways to Use Adobe Express at School

    May 24, 2023

    EOS Education Achieves Education Partner Specialization in Google Cloud Partner Advantage

    May 22, 2023

    Online summer reading

    May 20, 2023
Teaching Resources Pro
Home»IT»OSC&R Supply Chain Security Framework goes live on Github
IT

OSC&R Supply Chain Security Framework goes live on Github

March 31, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

The supporters of the Open Software Supply Chain Attack Reference (CSO&R) for Supply Chain Security has been uploaded to Github, allowing anyone to contribute to the model.

The MITER ATT&CK-like framework was launched in February with the stated goal of helping security teams improve their understanding of, assess, and contain software supply chain threats.

Directed by Beef Safety, an Israel-based supply chain specialist, project backers include David Cross, former head of cloud security at Microsoft and Google; Neatsun Ziv, co-founder and CEO of Ox Security; Lior Arzi, co-founder and CPO at Ox Security; Hiroki Suezawa, senior security engineer at GitLab; Eyal Paz, head of research at Ox Security; Chenxi Wang, former OWASP Global Board Member; Shai Sivan, CISO at Kaltura; Naor Penso, product safety manager at FICO; and Roy Feintuch, former CTO of Cloud at Check Point.

“After launching OSC&R, we were inundated with emails from people working on things within OSC&R who wanted to contribute,” said Neatsun Ziv, who served as Check Point’s vice president of cybersecurity before founding Ox.

“By switching to Github and by opening the project to contributions, we hope to capture this collective knowledge and experience for the benefit of the entire security community.

Meanwhile, Visa product security Dineshwar Sahni also joined the consortium, while former NSA director Mike Rogerswho led the US intelligence agency from 2014 to 2018, lent his support to the project.

“Cybersecurity is a game of cat and mouse,” Rogers said. “Getting the upper hand requires building a good threat model and OSC&R enables organizations to identify security requirements, identify potential security threats and vulnerabilities, quantify the criticality of threats and vulnerabilities, and prioritize remedial methods.”

Sahni added, “In an episode of Star Trek, while working on the Enterprise’s vulnerabilities to the threat actor, Mr. Spock said, ‘Insufficient facts always invite danger, Captain!’ “. The same is certainly true in the field of cybersecurity, where the lack of information increases vulnerability. By increasing community knowledge, OSC&R holds enormous potential to mitigate dangers to the software supply chain and reduce the attack surface more broadly.

The framework’s backers believe their project will prove extremely valuable to companies looking to scale their software supply chain security programs. Among other things, it can help assess existing defenses, set criteria for prioritizing threats, and track attacker group behaviors.

The need for organizations to prioritize the resilience of their software supply chains has been hammered home repeatedly over the past few years, with arguably the most impactful incident being the SolarWinds incident of 2020/1which began when Russian threat actors compromised the company’s Orion networking platform and injected backdoor malware that was then shipped to customers as a “tainted” update .

History repeats itself today, as evidenced by an incident still in development within the unified communications company 3CXwhich began when a product update shipped with a security issue exploited by a threat actor with ties to the North Korean regime.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How to Join a Node to a Docker Swarm

May 28, 2023

Five key steps when there is a risk of a fraud investigation

May 26, 2023

8 VS Code extensions you didn’t know you needed

May 24, 2023
Add A Comment

Leave A Reply Cancel Reply

Latest

What is Pocketalk? The translation tool explained

May 28, 2023

Taking care of yourself during and after exam season – Student Blog

May 28, 2023

Ohio teacher shortage: As schools review vacancies, teachers fill gaps – cleveland.com

May 28, 2023

Assad’s normalization leaves Syrians in Rukban’s camp fearful of the future – Al Jazeera

May 28, 2023

Subscribe to Updates

Get the latest creative news from teachingresourcespro.

We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't miss

What is Pocketalk? The translation tool explained

May 28, 2023

Taking care of yourself during and after exam season – Student Blog

May 28, 2023

Ohio teacher shortage: As schools review vacancies, teachers fill gaps – cleveland.com

May 28, 2023

Subscribe to Updates

Get the latest creative news from teachingresourcespros.

  • Home
  • Contact us
  • Privacy policy
  • Terms & Conditions
© 2023 Designed by teachingresourcespro .

Type above and press Enter to search. Press Esc to cancel.