Building safer machine learning systems – A Threat Model
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/august/building-safer-machine-learning-systems-a-threat-model/
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/august/building-safer-machine-learning-systems-a-threat-model/
Есть практические материалы по криптографии
https://ctcrypt.ru/materials2019
https://ctcrypt.ru/materials2019
Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF) | CSRC
https://csrc.nist.gov/publications/detail/white-paper/2019/06/11/mitigating-risk-of-software-vulnerabilities-with-ssdf/draft
https://csrc.nist.gov/publications/detail/white-paper/2019/06/11/mitigating-risk-of-software-vulnerabilities-with-ssdf/draft
CSRC | NIST
Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF) (Draft)
Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure the software being developed is well secured. This white paper…
Forwarded from Oleks Bodryk
webinar-calendar-june-2019---bt_508950.pdf
130.6 KB
webinar-calendar-june-2019---bt_508950.pdf
Senator asks Department of Justice if it can keep a lid on its software exploits
https://www.cyberscoop.com/department-of-justice-hacking-tools-ron-wyden-letter/
https://www.cyberscoop.com/department-of-justice-hacking-tools-ron-wyden-letter/
CyberScoop
Senator asks Department of Justice if it can keep a lid on its software exploits
In recent years, Department of Justice agencies have quietly acquired and deployed hacking tools in support of their law enforcement mission. A handful of high-profile cases have brought greater scrutiny to those efforts, most notably in 2016 when the FBI…
Интересная тенденция, похоже эксплойты постепенно становятся полноценным нематериальным активом для защиты которых возможно выпустят отдельный НПА.... В США.
Проектируете awareness учебный курс? Задумайтесь над концепцией микроуроков.
https://medium.com/sans-security-awareness/5-reasons-to-consider-micro-learning-for-your-security-awareness-training-program-a058f5098239
https://medium.com/sans-security-awareness/5-reasons-to-consider-micro-learning-for-your-security-awareness-training-program-a058f5098239
Medium
5 Reasons to Consider Micro-Learning for Your Security Awareness Training Program
By Andrew Mantuano
На прошлой неделе Брюс Шнаер проводил Workshop on the Economics of Information Security в Гарварде. По линку описание докладов и сами доклады. Рекомендуются к просмотру.
https://www.lightbluetouchpaper.org/2019/06/03/weis-2019-liveblog/
https://www.lightbluetouchpaper.org/2019/06/03/weis-2019-liveblog/
Учебные материалы по одной из самых популярных и бесплатных платформ threatexchange misp.
https://twitter.com/MISPProject/status/1138512182625427457?s=09
https://twitter.com/MISPProject/status/1138512182625427457?s=09
Twitter
MISP
Joining us at the @FIRSTdotOrg #firstcon19 next Monday and Tuesday for the @MISPProject training session - don't hesitate to download the VM before joining us https://t.co/oy4fUeBphW and the training materials are already available here https://t.co/I3bDu9QlaZ…