Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris Hughes -- Software Transparency

39 min20 januari 2024

Om avsnittet

Chris Hughes, co-founder of Aquia, joins Chris and Robert on the Application Security Podcast to discuss points from his recent book Software Transparency: Supply Chain Security in an Era of a Software-Driven Society, co-authored with Tony Turner. The conversation touches on the U. government in the software supply chain, the definition and benefits of software transparency, the concept of a software bill of materials (SBOM), and the growth of open-source software. Chris Hughes is a proven cloud cybersecurity leader. with nearly 20 years of experience in the federal and commercial industries. Chris has a dynamic skill set with a blend of IT, cyber cloud security, and DevSecOps experience.

Connect with Chris Hughes:
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Application Security Program Handbook

Mentioned in this episode:
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
Application Security Program Handbook
Agile Application Security
CNCF Catalog of Supply Chain Compromises
Aquia
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
OpenSSF
OpenSSL
Let's Encrypt
Sigstore
Minimum Viable Secure Product
Executive Order 14028
Agile Application Security: Enabling Security in a Continuous Delivery Pipeline
The Application Security Program Handbook by Derek Fisher

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Chris Hughes: Software Transparency
03:42 Yeah, and you're, uh, you're co author of the latest book
04:31 Yeah, one thing that I kind of went down the thought
08:13 Yeah, yeah, and I think it's going to become a bigger
09:37 I think we've got, uh, we've got a couple different angles
11:52 Yeah, that's, that's always, you know, security and privacy, not privacy
15:32 I mean, that's why, when you think about one of the
17:01 Yeah, we're talking about the funding of nation states. Right, they
20:10 Yeah. So I've, uh, you know, I've kind of been waiting
22:48 Yeah. This is a weird situation in the sense that, you
25:14 Yeah. I mean, it's definitely a real risk. Uh, I feel
28:54 Yeah, that's, that's, but that's the reality of the, the world
31:51 All right. Well, let's, uh, let's talk about the, the kind
35:23 A billboard, what would it say for a message if you
37:14 Then, uh, yeah, Derek, excuse me, Derek was a guest on

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.