Loading…
November 12, 2024 | Salt Lake City, Utah
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SigstoreCon Supply Chain Day 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Standard Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
Tuesday November 12, 2024 4:30pm - 5:00pm MST
The US Cybersecurity and Infrastructure Security Agency (CISA) leads the national effort to understand, manage, and reduce risk to critical cyber infrastructure. This requires vulnerability management processes based on well illuminated data. But gaps are visible at the intersection of software identification and supply chain management tools and automation. Software identifiers may be invisible or too opaque to be sufficiently effective for vulnerability management at scale or at later points along a supply chain. This lightning talk will describe a funding initiative recently announced by CISA and the US Department of Homeland Security’s Science and Technology Directorate to improve usability and scalable implementations of intrinsic identifiers, artifact dependency graph (ADG) generation, and distribution of ADG’s along with typical supply chain artifacts. The Silicon Valley Innovation Program (SVIP) Other Transaction Solicitation (OTS) Topic Call 70RSAT24R00000042 aims to invest in startups advancing the state of the art in ways which likely benefit CISA’s vulnerability management work. AND do so with foundational technologies implemented as open source!
Speakers
avatar for Timothy Pepper

Timothy Pepper

Senior Technical Advisor, Open Source Software Security, Cybersecurity and Infrastructure Security Agency
Tim Pepper is an engineer with over 25 years in open source, with contributions to Kubernetes (emeritus Steering Committee elected member, emeritus Code of Conduct Committee elected member; past SIG Release co-chair and WG LTS co-organizer), open source security projects, Linux kernel/drivers/distributions... Read More →
Tuesday November 12, 2024 4:30pm - 5:00pm MST
Alpine

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link