Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile
Allan is @allanfriedman on bsky & infosec.exchange

@allanfriedman

#SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.

ID: 46715219

calendar_today12-06-2009 18:34:06

15,15K Tweet

6,6K Takipçi

1,1K Takip Edilen

Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile Photo

Registration is now open for SBOM-a-Rama Fall 2024. This year, introducing the SBOM Solution Showcase. Come join us (online or in Denver) in September! cisa.gov/news-events/ev…

Registration is now open for SBOM-a-Rama Fall 2024.  This year, introducing the SBOM Solution Showcase. Come join us (online or in Denver) in September! 
cisa.gov/news-events/ev…
OpenSSF (@openssf) 's Twitter Profile Photo

🎙️ New episode: "What’s in the SOSS?" CRob chats with Adolfo García Veytia (puerco) about the fascinating world of Software Bills of Materials (SBOMs) and VEX. Discussion on #SBOM standards, VEX's role in reducing false positives, and much more! 🚀 hubs.la/Q02Cd0040

🎙️ New episode: "What’s in the SOSS?" CRob chats with Adolfo García Veytia (<a href="/puerco/">puerco</a>) about the fascinating world of Software Bills of Materials (SBOMs) and VEX. Discussion on #SBOM standards, VEX's role in reducing false positives, and much more! 🚀

hubs.la/Q02Cd0040
Brian in Pittsburgh (@arekfurt) 's Twitter Profile Photo

But of course that's not at all how Microsoft and many others do use them today. Today, security defaults are still too often representative of nothing but a lowest common denominator approach to customer security needs.

Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile Photo

Some good points on the economics there. Not sure I agree with the conclusion, but more people (esp in positions like mine and my agency's) should grapple with this essay.

Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile Photo

Living the “champagne lounge, steerage seats” lifestyle. Looking forward to a great week in Seoul, talking about supply chain security, OSS, and—of course—#SBOM

Living the “champagne lounge, steerage seats” lifestyle. Looking forward to a great week in Seoul, talking about supply chain security, OSS, and—of course—#SBOM
Cybersecurity and Infrastructure Security Agency (@cisagov) 's Twitter Profile Photo

The updated Software Bill of Materials (SBOM) Frequently Asked Questions (FAQ) provides information on the benefits of SBOM, common misconceptions and concerns, creation of an SBOM, distributing and sharing an SBOM, and role specific guidance. go.dhs.gov/37S

The updated Software Bill of Materials (SBOM) Frequently Asked Questions (FAQ) provides information on the benefits of SBOM, common misconceptions and concerns, creation of an SBOM, distributing and sharing an SBOM, and role specific guidance. go.dhs.gov/37S
Philippe Ensarguet (@p_ensarguet) 's Twitter Profile Photo

If you are curious about what #SBOM, #SLSA and #Scorecard are, and how they inter-relate to strengthen #software #security and #trust, you should read this post from @cpswan 👇 blog.thestateofme.com/2024/07/22/sup…

Eric Geller (@ericgeller) 's Twitter Profile Photo

DHS says CISA’s test of AI vulnerability detection methods (required by Biden’s AI EO) determined that “the best use of AI for vulnerability detection currently lies in supplementing and enhancing, as opposed to replacing, existing tools.” dhs.gov/news/2024/07/2…

DHS says CISA’s test of AI vulnerability detection methods (required by Biden’s AI EO) determined that “the best use of AI for vulnerability detection currently lies in supplementing and enhancing, as opposed to replacing, existing tools.” dhs.gov/news/2024/07/2…
Viktor Petersson (@vpetersson) 's Twitter Profile Photo

Just released an exciting episode of "Nerding Out with Viktor" featuring Allan is @allanfriedman on bsky & infosec.exchange from Cybersecurity and Infrastructure Security Agency! We dive into Software Bill of Materials (SBOMs) and their crucial role in cybersecurity. Don't miss this deep dive into the future of secure software! Catch the full episode on

Mohammad-Ali A'RÂBI (@mohammadalien) 's Twitter Profile Photo

Did you know Docker has an integration for SBOM generation? $ docker sbom gitweekly/git-weekly On Docker Engine you can install it manually. github.com/docker/sbom-cl…

Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile Photo

Setting up for our first ever SBOM Solutions Showcase! This Denver ballroom will be filled with 24 organizations from around the world to meet your #sbom needs, with many more listed online. cisa.gov/resources-tool…

Setting up for our first ever SBOM Solutions Showcase!  This Denver ballroom will be filled with 24 organizations from around the world to meet your #sbom needs, with many more listed online.

cisa.gov/resources-tool…
Allan is @allanfriedman on bsky & infosec.exchange (@allanfriedman) 's Twitter Profile Photo

In case you missed my news elsewhere: This will be my last week at CISA. I’m sad to be leaving a great team, but very excited for some new projects. And don’t worry—I’ll be finding ways to help out with #SBOM! meritalk.com/articles/cisa-…