Artwork

内容由VMware提供。所有播客内容(包括剧集、图形和播客描述)均由 VMware 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

Securing the Software Supply Chain with Chip Childers, VP Security at VMware and Jim Mercer, VP DevSecOps at IDC

44:57
 
分享
 

Manage episode 380825340 series 2623537
内容由VMware提供。所有播客内容(包括剧集、图形和播客描述)均由 VMware 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.

Key Quotes:

“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip

“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim

---------

Timestamps:

(01:15) Why are we concerned about the software supply chain?

(05:25) Building complex systems on top of other complex systems

(08:15) Realizations from the Log4j incident

(11:22) Resulting shifts from new compliance and regulations

(16:21) Creative chaos in the software industry

(18:48) Reliance on the open-source community

(19:23) How can you identify where code is coming from?

(20:17) Prioritizing vulnerabilities

(23:08) The snowball effect in the supply chain

(25:00) How do you understand your exposure?

(33:15) The impact of generative AI

(37:27) Where should CIOs start heading into board level conversations?

--------

Links:

Chip Childers on LinkedIn

Jim Mercer on LinkedIn

CIO Exchange on Twitter

Yadin Porter de León on Twitter

[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio

  continue reading

73集单集

Artwork
icon分享
 
Manage episode 380825340 series 2623537
内容由VMware提供。所有播客内容(包括剧集、图形和播客描述)均由 VMware 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.

Key Quotes:

“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip

“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim

---------

Timestamps:

(01:15) Why are we concerned about the software supply chain?

(05:25) Building complex systems on top of other complex systems

(08:15) Realizations from the Log4j incident

(11:22) Resulting shifts from new compliance and regulations

(16:21) Creative chaos in the software industry

(18:48) Reliance on the open-source community

(19:23) How can you identify where code is coming from?

(20:17) Prioritizing vulnerabilities

(23:08) The snowball effect in the supply chain

(25:00) How do you understand your exposure?

(33:15) The impact of generative AI

(37:27) Where should CIOs start heading into board level conversations?

--------

Links:

Chip Childers on LinkedIn

Jim Mercer on LinkedIn

CIO Exchange on Twitter

Yadin Porter de León on Twitter

[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio

  continue reading

73集单集

所有剧集

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南