我们的世界安全了吗?我们接近了吗?.pdf

编号:612411 PDF 10页 532KB 下载积分:VIP专享
下载报告请您先登录!

我们的世界安全了吗?我们接近了吗?.pdf

1、October 11,2024C I S A|C Y B E R S E C U R I T Y A N D I N F R A S T R U C T U R E S E C U R I T Y A G E N C YIS OUR WORLD SECURE YET?(ARE WE EVEN CLOSE?):AN UPDATE ON CISAS SECURE BY DESIGN INITIATIVEKIRK LAWRENCE1October 11,2024Secure by Design Is HardIntroduction3October 11,2024In the past 18 mon

2、ths,CISA has1.Preached the gospel of Secure by Design2.Released the Secure by Design Pledge3.Published 6 Secure by Design Alerts and 11 Secure by Design Blogs4.Established a Working Group with CISA to coordinate SbD activities across 8 disparate workstreams.5.Continue to advance Software Bill-of-Mat

3、erials(SBOM)adoption across the USG and internationally,focusing on scaling and operationalizing SBOM tools to improve visibility into software products.6.Published an Open Source Software Security Roadmap that lays out our priorities for securing the open source software ecosystem.Worked to increas

4、e broad understanding of SbD principles in OS SW use and development.Background5October 11,20241.Manufacturers should take ownership of the security outcomes for their customers.The burden of safety should never fall solely upon the customer.2.Manufacturers should embrace radical transparency and ac

5、countability.3.Manufacturers should build organization structure and leadership to ensure safety is built in.Principles6October 11,2024Within a year,demonstrate measurable progress in the following areas:1.Increase the use of multi-factor authentication(MFA).2.Reduce default passwords across product

6、s.3.Reduce entire classes of vulnerabilities.4.Increase the installation of security patches by customers.5.Publish a vulnerability disclosure policy(VDP).6.Transparency in vulnerability reporting.(CVE)7.Increase in the ability for customer

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(我们的世界安全了吗?我们接近了吗?.pdf)为本站 (小小) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠