<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Managing Open Source Vulnerabilities in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/61709#M4023</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;&amp;nbsp; If you were a partner of my organisation, you would have access to the resources you have requested.&amp;nbsp; Unfortunately, I am prohibited from sharing, unless I obtain special permission to do so, this is by corporate policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, as you can imagine we have a deep depth of knowledge in Open Source as a developer over many years.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is some guidance here:&amp;nbsp; &lt;A href="https://www.ibm.com/opensource/enterprise/" target="_blank" rel="noopener"&gt;https://www.ibm.com/opensource/enterprise/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is our history:&amp;nbsp; &lt;A href="https://www.ibm.com/opensource/story/" target="_blank" rel="noopener"&gt;https://www.ibm.com/opensource/story/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may find some links, articles which may be of use to you and others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out this as well:&amp;nbsp; &lt;A href="https://openssf.org/" target="_blank" rel="noopener"&gt;https://openssf.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check out these guides too:&amp;nbsp; &lt;A href="https://openssf.org/resources/guides/" target="_blank"&gt;https://openssf.org/resources/guides/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2023 21:33:07 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2023-08-15T21:33:07Z</dc:date>
    <item>
      <title>Managing Open Source Vulnerabilities</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/32909#M2358</link>
      <description>&lt;P&gt;Calling all commercial software developers! How does your organization manage Open Source libraries/components in your builds? Do you have a centralized repository to manage your "inventory"? What is your organizations policy for vulnerability remediation? Is it the same as commercial software?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:26:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/32909#M2358</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Managing Open Source Vulnerabilities</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/61691#M4021</link>
      <description>&lt;P&gt;My organization is in the process of developing our open-source policies.&amp;nbsp; &amp;nbsp;We are looking for guidance from organizations such as NIST and CSF but there seems to be scant little out there.&amp;nbsp; &amp;nbsp;This doesn't answer your question aside from saying that we're working on it. #open source&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 13:22:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/61691#M4021</guid>
      <dc:creator>cclements</dc:creator>
      <dc:date>2023-08-15T13:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Managing Open Source Vulnerabilities</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/61709#M4023</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;&amp;nbsp; If you were a partner of my organisation, you would have access to the resources you have requested.&amp;nbsp; Unfortunately, I am prohibited from sharing, unless I obtain special permission to do so, this is by corporate policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, as you can imagine we have a deep depth of knowledge in Open Source as a developer over many years.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is some guidance here:&amp;nbsp; &lt;A href="https://www.ibm.com/opensource/enterprise/" target="_blank" rel="noopener"&gt;https://www.ibm.com/opensource/enterprise/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is our history:&amp;nbsp; &lt;A href="https://www.ibm.com/opensource/story/" target="_blank" rel="noopener"&gt;https://www.ibm.com/opensource/story/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may find some links, articles which may be of use to you and others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check out this as well:&amp;nbsp; &lt;A href="https://openssf.org/" target="_blank" rel="noopener"&gt;https://openssf.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check out these guides too:&amp;nbsp; &lt;A href="https://openssf.org/resources/guides/" target="_blank"&gt;https://openssf.org/resources/guides/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 21:33:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Managing-Open-Source-Vulnerabilities/m-p/61709#M4023</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-08-15T21:33:07Z</dc:date>
    </item>
  </channel>
</rss>

