Skip to content

Commit

Permalink
Merge pull request #79 from oasis-open/communitydays
Browse files Browse the repository at this point in the history
Community Days
  • Loading branch information
tschmidtb51 authored Nov 28, 2024
2 parents 93046d7 + 27423a9 commit 5601d51
Showing 1 changed file with 5 additions and 5 deletions.
10 changes: 5 additions & 5 deletions communitydays/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -297,7 +297,7 @@ <h3>CSAF Community Day 2 (December 13, 2024)</h3>
<tr>
<td>14:00 - 14:45 CET</td>
<td><a href="#experiences-consuming-csafs-a">Experiences in Consuming CSAFs & What is Still Missing</a></td>
<td>Tobi & Michael</td>
<td>Tobias Limmer & Michael Pfurtscheller</td>
</tr>
<tr>
<td>14:50 - 15:15 CET</td>
Expand Down Expand Up @@ -491,18 +491,18 @@ <h4>Speaker: Dr. Salva Daneshgadeh Cakmakci</h4>
<div class="session" id="experiences-consuming-csafs">
<h3>Experiences in Consuming CSAFs & What is Still Missing</h3>
<h4>Speaker: Tobias Limmer & Michael Pfurtscheller</h4>
<p><strong>Abstract:</strong> Siemens not only publishes CSAFs (Common Security Advisory Framework) but also consumes advisories through an automated process. Tobi will provide insights into his experiences with processing CSAF data and matching it against assets, highlighting potential improvements in the CSAF specification.
<p><strong>Abstract:</strong> Siemens not only publishes CSAFs (Common Security Advisory Framework) but also consumes advisories through an automated process. Tobias Limmer will provide insights into his experiences with processing CSAF data and matching it against assets, highlighting potential improvements in the CSAF specification.
While Security Advisories are necessary and helpful, vulnerabilities are ultimately resolved through updates/patching of hard and software.
Michael will discuss the challenges of consuming and publishing updates from different perspectives within the supply chain, covering roles such as:
Michael Pfurtscheller will discuss the challenges of consuming and publishing updates from different perspectives within the supply chain, covering roles such as:
<ul>
<li>Hardware or Software Component Developers</li>
<li>Product & Device Manufacturers</li>
<li>Solution and Application Developers</li>
<li>Product Integrators like Factory Operators, Car Manufacturers, etc.</li>
</ul>
</p>
<p><strong>Bio Tobi:</strong> Tobi has been in the security field for 20 years, with over a decade of experience focused on the industrial side of IT infrastructures. He began his journey with vulnerability handling at Siemens ProductCERT, where he played a key role in automating security tests. His current research areas include tool-based vulnerability management and risk-based mitigation decisions.</p>
<p><strong>Bio Michael:</strong> Michael is a Product Security Manager at u-blox AG but has mainly worked as a consultant since 1998. Security was always part of the job when working in the fields of SAP programming, management of messaging and collaboration infrastructures, network and computing center infrastructures, e-commerce projects and Pentesting. Currently, he focuses on establishing an ISO 21434-compliant Cybersecurity Management System (CSMS) for u-blox and its GNSS and IoT products, including vulnerability, incident, and update management for its modules and firmware.</p>
<p><strong>Bio Tobias Limmer:</strong> Tobias Limmer has been in the security field for 20 years, with over a decade of experience focused on the industrial side of IT infrastructures. He began his journey with vulnerability handling at Siemens ProductCERT, where he played a key role in automating security tests. His current research areas include tool-based vulnerability management and risk-based mitigation decisions.</p>
<p><strong>Bio Michael Pfurtscheller:</strong> Michael Pfurtscheller is the Product Security Manager at u-blox AG but has mainly worked as a consultant since 1998. Security was always part of the job when working in the fields of SAP programming, management of messaging and collaboration infrastructures, network and computing center infrastructures, e-commerce projects and Pentesting. Currently, he focuses on establishing an ISO 21434-compliant Cybersecurity Management System (CSMS) for u-blox and its GNSS and IoT products, including vulnerability, incident, and update management for its modules and firmware.</p>
</div>
<a class="anchor" id="csaf-contracts-a"></a>
<div class="session" id="csaf-contracts">
Expand Down

0 comments on commit 5601d51

Please sign in to comment.