Army Not Ready for February SBOM Deadline

Army Not Ready for February SBOM Deadline

Interview with government IT “Reformer” John Weiler By Deb Radcliff, editor of TalkSecure, sponsored by CodeSecure and syndicated at Security Boulevard & YouTube Starting in February 2025, the U.S. Army will require software bills of materials (SBOMs) for new software contracts. The requirements apply to all "covered computer software," whether developed by government ... Read More
Secure by Demand with Dick Brooks

Empowering Software Buyers Through Secure-by-Demand Guidelines

| | cisa, sdlc, TalkSecure Blog
Interview by Deb Radcliff, editor of TalkSecure, hosted by CodeSecure and syndicated at YouTube, Bright Talk, and Security Boulevard Recently, the Cybersecurity and Infrastructure Security Agency (CISA) released its Secure by Demand Guide for technology buyers to drive adoption of its established Secure by Design guidance for product manufacturers.  The ... Read More
EU CRA: Good Intentions, Impossible Requirements

EU CRA: Good Intentions, Impossible Requirements

As the European Union’s Cyber Resilience Act (EU CRA) prepares to publish a final draft, product manufacturers with any “digital” component must comply three years after final publication. If passed, the EU CRA will be enacted into law and enforced by penalties. The act aims to reduce vulnerabilities in products ... Read More

Gen-AI Won’t Replace Humans – or SAST – In the SDLC

Interview with MITRE’s Tracey Bannon by industry analyst Deb Radcliff, editor of TalkSecure, hosted by CodeSecure and syndicated at Security Boulevard & YouTube Click HERE to listen. Whether people realize it or not, AI in the form of machine learning is already enhancing today’s advanced software testing and development tool sets. Now, with ... Read More

Threat Modeling for Embedded Systems

| | TalkSecure Blog
By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube) In this interview, Jay Warne describes his work on what he calls ‘far-side of research’ into low-level functions of embedded devices serving the energy, industrial, and manufacturing sectors. Having come from a development background himself, he looks at ... Read More
SBOMs Critical to Software Supply Chain Security

SBOMs Critical to Software Supply Chain Security

By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube)LAS VEGAS – One day before the Black Hat Briefings started in Vegas last week, a group of experts met at the Wynn Las Vegas to talk about SBOMs (software bills of materials) during the Software Supply Chain Security ... Read More

Toil Not: Automate DevOps Governance

By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube) In this show, Deb interviews two innovative technologists driving the DevOps Automated Governance movement. They’re both authors, prolific writers, speakers, and contributors to reference architectures and other materials supporting Automated DevOps Governance ... Read More

How Much Data Do You Need From Your SBOM?

By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube) If we think of Software Bills of Materials as an ingredient list for critical software products, the question becomes, ‘how thorough do we need that ingredient list to be?’ In other words, ... Read More

How SBOM Data Enhances Cybersecurity and Response Operations

By Deb Radcliff, DevSecOps analyst and editor of CodeSecure’s TalkSecure educational content (syndicated at Security Boulevard & YouTube) At the RSA Security Conference (RSAC) last month, a multitude of vendors and speakers talked about Software Bills of Materials (SBOMs), which I posted about in my RSAC follow up article. In ... Read More

White House Urges Tossing C and C++ From Critical Infrastructure Systems… and why this is not a good idea.

"the way coders do their work is of critical importance to national interest" -- white house ONCD The post White House Urges Tossing C and C++ From Critical Infrastructure Systems… and why this is not a good idea. appeared first on CodeSecure ... Read More