Vulnerability Management, CYBEX Standards and Automation

FIRST/TF-CSIRT Seminar

Tuesday — January 29th, 2013 15:45

In order to reduce exposure, improve efficiency and improve service quality, Deutsche Telekom has newly implemented a threat and vulnerability management system. This system process security advisories and network-layer vulnerabilities address them to the system owners and generate alerts, reports and management-like KPIs. In this session we will discuss the current market maturity stage for tools that are able to process CYBEX standards (CPE, CVRF, etc), give an overview of the project requirements and market evaluation, discuss about the current challenges and pitfalls in this field and provide valuable lessons learned.

Presenters

  • Joao Collier de Mendonca (Senior Security Advisor at Deutsche Telekom CERT)