Evo Cyber Security #46 - Application Security Risks in Open Source Supply Chains
Aug 23, 2023
auto_awesome
Experts Veroniki Stamati-Koromina, Sean Wright, Keith Batterham, and Chris Jackson discuss the risks and vulnerabilities in open source supply chains. They emphasize the need for managing risks, prioritizing and remediating issues, and the potential for hidden malicious code in libraries. The speakers also highlight the importance of effective communication, evaluating vulnerabilities beyond CVSS scores, and the significance of knowledge in the recruitment industry.
Fast development often leads to including open source codes, introducing unknown security risks.
Properly assessing vulnerable code and communicating product risks to organizational leadership are crucial.
Deep dives
The Risk of Open Source Supply Chains
The discussion revolves around the risks organizations face when utilizing open source solutions. The guests discuss how the need for fast development often leads to the inclusion of open source codes, repositories, and libraries. However, this introduces security risks as the security standards and vulnerabilities of those components may be unknown. The increasing reliance on open source supply chains also heightens the organization's exposure to technology security risks, potentially introducing vulnerabilities beyond their control.
Managing the Risk of Dependencies
The conversation delves into the challenges of managing supply chain risks, particularly related to third-party dependencies and configuration management. The guests emphasize the importance of properly assessing vulnerable code and making informed decisions about open source components. They highlight the need for diligent management of software dependencies, utilizing tools like Sneak, and implementing processes that prioritize remediating the identified risks. The guests also discuss the importance of addressing code quality issues and ensuring that unused or orphan libraries are removed.
Communicating Product Risks to Leadership
The podcast touches upon the importance of effectively communicating product risks to organizational leadership. The guests stress the need to speak the language of business leaders and frame the discussion around risk and revenue. They emphasize the significance of quantifying the value of risks in terms of their impact on business functions and revenue generation. The guests further highlight the importance of prioritizing security concerns, utilizing a layered approach to testing, and addressing vulnerabilities that could have a direct impact on revenue and the organization's overall security posture.
Join host Gareth Davies in Episode 46 of Evo Cyber Security as he delves into the critical topic of "Application Security Risks in Open Source Supply Chains." In this episode, experts from the field, Veroniki Stamati-Koromina of Flutter Entertainment, Sean Wright of Featurespace, Keith Batterham from Kontex, and Chris Jackson of Flo Health, provide invaluable insights into the challenges and solutions within application security. Learn from these industry leaders as they discuss the ever-evolving landscape of cyber threats and how organizations can protect their software in an open-source world.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode