Artwork

VMware에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 VMware 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Securing the Software Supply Chain with Chip Childers, VP Security at VMware and Jim Mercer, VP DevSecOps at IDC

44:57
 
공유
 

Manage episode 380825340 series 2623537
VMware에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 VMware 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.

Key Quotes:

“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip

“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim

---------

Timestamps:

(01:15) Why are we concerned about the software supply chain?

(05:25) Building complex systems on top of other complex systems

(08:15) Realizations from the Log4j incident

(11:22) Resulting shifts from new compliance and regulations

(16:21) Creative chaos in the software industry

(18:48) Reliance on the open-source community

(19:23) How can you identify where code is coming from?

(20:17) Prioritizing vulnerabilities

(23:08) The snowball effect in the supply chain

(25:00) How do you understand your exposure?

(33:15) The impact of generative AI

(37:27) Where should CIOs start heading into board level conversations?

--------

Links:

Chip Childers on LinkedIn

Jim Mercer on LinkedIn

CIO Exchange on Twitter

Yadin Porter de León on Twitter

[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio

  continue reading

73 에피소드

Artwork
icon공유
 
Manage episode 380825340 series 2623537
VMware에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 VMware 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.

Key Quotes:

“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip

“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim

---------

Timestamps:

(01:15) Why are we concerned about the software supply chain?

(05:25) Building complex systems on top of other complex systems

(08:15) Realizations from the Log4j incident

(11:22) Resulting shifts from new compliance and regulations

(16:21) Creative chaos in the software industry

(18:48) Reliance on the open-source community

(19:23) How can you identify where code is coming from?

(20:17) Prioritizing vulnerabilities

(23:08) The snowball effect in the supply chain

(25:00) How do you understand your exposure?

(33:15) The impact of generative AI

(37:27) Where should CIOs start heading into board level conversations?

--------

Links:

Chip Childers on LinkedIn

Jim Mercer on LinkedIn

CIO Exchange on Twitter

Yadin Porter de León on Twitter

[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio

  continue reading

73 에피소드

모든 에피소드

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드