Earlier today we joined Jake Kouns, CISO of Risk Based Security, and Christine Gadsby, Director of Product Security at BlackBerry for a guest webcast. They gave their Black Hat 2016 talk ‘OSS Security Maturity: Time to Put on Your Big Boy Pants’ which analyzes the real risks of using OSS and the best way to manage its use within your organization.
This post is a high-level review of that presentation–you can watch the recording here and download their slides here.
This presentation follows our recent webcast by Kymberlee Price on building useful and practical product security incident response teams and processes, an extended version of the presentation she gave during Black Hat 2016, titled ‘Building a Product Security Incident Response Team: Learnings from the Hivemind.’ In that presentation, Kymberlee outlines some frameworks, processes, and ideas to consider when setting up a PSIRT, touching on the additional responsibility and necessary processes when dealing with OSS.
Why do we care? Working with the security research community to find bugs faster and more seamlessly is crucial to product security, and crucial when utilizing OSS. Bug bounties and responsible disclosure policies referred to in Level 3 of BlackBerry’s Open Source Software Maturity Model, are a fantastic way to build that relationship.
For more in-depth context on these challenges and this custom OSS Maturity model with additional examples and considerations, watch the webcast, and feel free to reach out to Jake and Christine with any questions.