Cloud Security Podcast by Google

EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!

11 snips
Feb 20, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Google's Vulnerability Coordination Center

  • Google's Vulnerability Coordination Center (VCC) handles vulnerabilities across OS, applications, firmware, and hardware.
  • The VCC coordinates fixes, informs customers, and partners with internal teams and the industry.
INSIGHT

Vulnerability Prioritization

  • Google prioritizes vulnerabilities based on severity, system applicability, and active exploitation.
  • No "magic AI" exists; they use similar metrics as other companies, emphasizing practical considerations.
ANECDOTE

Google's Monorepo

  • Google's large monorepo, while complex, offers control over software and dependencies through code reviews and visibility rules.
  • Calculating dependencies across billions of lines of code can be time-consuming, reminiscent of XKCD's "compiling" comic.
Get the Snipd Podcast app to discover more snips from this episode
Get the app