FedRAMP, Software Supply Chain Guidance & API Security New Year Updates - Ep 51 episode artwork

EPISODE · Jan 18, 2023 · 15 MIN

FedRAMP, Software Supply Chain Guidance & API Security New Year Updates - Ep 51

from Reimagining Cyber - real world perspectives on cybersecurity · host Reimagining Cyber

“I think with any metric, the FedRAMP program has been viewed as...."Listen to this edition of Reimagining Cyber EXTRA and find out what Rob and Stan think about FedRAMP.Firstly, what is it?!“[FedRAMP’s] whole purpose is to provide a standardized government-wide approach to security assessment, authorization, and continuing monitoring of cloud products and services used by the federal government agencies.”Plus:- FedRAMPs codification into law via the National Defense Authorization Act (NDAA)- Action to making the process easier for vendors and agencies.- Establishment of the Federal Secure Cloud Advisory Committee – what is it, what’s it for?- Why does the NDAA not make vendors provide a SBOM? Will this change?“The crystal ball is if you are a software supplier to the government, you have to be prepared in the future to be able to provide this kind of inventory of components that make up your software build. It's important to be able to react quickly to zero-days, to be able to understand what your software consists of to be able to mitigate open source security issues and risks”- Microsoft share how they manage supply chain risks with the Secure Supply Chain Consumption Framework (S2C2F). What does the OpenSSF think of it?“Everything that we're talking about in cyber always somehow turns itself back around to the software. The software supply chain is the common theme that we heard through last year. It's not going to slow down this year.”- The rise of APIs (application programming interface) as an attack surfaceAs featured on Million Podcasts' Best 100 Cybersecurity Podcasts  Top 50 Chief Information Security Officer CISO Podcasts Top 70 Security Hacking PodcastsThis list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!Follow or subscribe to the show on your preferred podcast platform.Share the show with others in the cybersecurity world.Get in touch via [email protected]

Episode metadata supplied by the publisher feed · Published Jan 18, 2023

Embed this episode

“I think with any metric, the FedRAMP program has been viewed as...." Listen to this edition of Reimagining Cyber EXTRA and find out what Rob and Stan think about FedRAMP. Firstly, what is it?! “[FedRAMP’s] whole purpose is to provide a standardized government-wide approach to security assessment, authorization, and continuing monitoring of cloud products and services used by the federal government agencies.” Plus: - FedRAMPs codification into law via the National Defense Authorization Act (N...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

FedRAMP, Software Supply Chain Guidance & API Security New Year Updates - Ep 51

0:00 15:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Reimagining Cyber - real world perspectives on cybersecurity?

This episode is 15 minutes long.

When was this Reimagining Cyber - real world perspectives on cybersecurity episode published?

This episode was published on January 18, 2023.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Reimagining Cyber - real world perspectives on cybersecurity episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!