The AppSec Management Podcast

Dr. Dag Flachet, Dr. Aram Hovsepyan

This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.

  1. 2h ago

    CRA Sessions: Vulnerability Management

    Vulnerability management is at the core of the Cyber Resilience Act (CRA). But what are the minimal expectations? Annex I, Part 2 lists 8 expectations manufacturers shall implement, yet they remain very abstract.Chapters:00:00 Introduction and a motivating example02:39 CRA: a brief recap08:11 Vulnerability management basics10:00 Revisiting the running example of a smart fridge10:38 Incident management18:25 The definition of an incident24:30 Defect management27:26 Security testing28:35 Patching and updating29:51 Secure deploy33:11 Recap of all required security activities under the CRAAbout this video:Today, the topic of vulnerability management typically makes one think of a SAST, DAST, IAST, SCA scanner. It makes us think of a triaging process and fixing the critical and high severity findings in the attempts to try to keep the risk low. However under the CRA vulnerability management is much broader. Fortunately, at least based on the OWASP SAMM latest benchmark, the industry is doing so much better on vulnerability management than on any other security related activities.Incident detection and response is the first major subtopic under vulnerability management. Especially in larger organizations most of the aspects of incident management are well under control. Amongst the key outstanding issues we typically face is the lack of communication between the product teams and the incident management teams as these are always siloed. Without a clear understanding of the business context the incident management can only focus on generic risks.Under the CRA the definition of an incident is interesting to understand. It differs starkly from the organizational perspective where a minor incident affecting a single user may be overlooked. CRA is all about the sensitivity of the data rather than the volume of the data.Defect management is about making sure that all findings are reported to a centralized defect tracking system, triaged and tackled within pre-defined time frames.Security testing is all about the tooling organizations are so excited about. However just pulling in a scanner is likely to make things worse. Teams must have a full grip on their scanners by tweaking the rulesets and how they tie to the build and deploy process.Patching and updating focuses on regularly patching OS and infrastructure components.Finally, secure deploy is actually a very complex topic as it needs to ensure the authenticity and integrity of the code moving from development to production. Code signing is one of the key controls, yet getting that aspect right is not as straightforward as it seems.All in all, you need a systematic approach to product security. Codific's SAMMY tool can help you out there. SAMMY can enable your gap assessment, improvement planning and demonstrating those improvements. SAMMY has an instrumental integration with JIRA so that your developers don't have to jump into a new tool. SAMMY also features an MCP server that allows your AI tools to generate all sorts of board reports based on your data in SAMMY.Links:👉 Use the SAMMY tool to manage your security posture: https://sammy.codific.com👉 Check the industry standard AppSec management model: https://owaspsamm.org

About

This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.