May 3, 2022, 8:44 p.m. | David Lindner, Director, Application Security

Security Boulevard securityboulevard.com




Insight #1




"How do you measure risk between vulnerabilities in custom code vs vulnerabilities in third-party code? To determine the real risk, I strongly encourage developers to start utilizing other measuring tools such as the Exploit Prediction Scoring System (EPSS). The reality shows us that a CVSS of 9 for a custom code vulnerability is not always as risky as a CVSS of 9 in a third-party library vulnerability."


 


Insight #2




"I get asked a lot about prioritization of “features” …

april ciso thought leaders

Information Security Engineers

@ D. E. Shaw Research | New York City

Embedded Penetration Tester - Cyber Security Team [BGSW]

@ Bosch Group | Warszawa, Poland

Staff Cybersecurity Engineer

@ Torc Robotics | Blacksburg, VA; Remote, US

Cybersecurity Engineer

@ Tiro Solutions Group LLC | Downers Grove, Illinois, United States

Director, Network Compliance

@ Marriott International | Bethesda, MD, United States

Cybersecurity Manager

@ Tiro Solutions Group LLC | Downers Grove, Illinois, United States