Trust us, information sharing can work. Here’s how we’re doing it.

You know what’s worse than trying to share cybersecurity information? Writing about it. Everyone has read over and over again about how important information sharing is for cybersecurity. The idea is certainly not new. It’s definitely not cool. It’s also hard. No one has completely nailed it even after talking about it for decades. Why is information sharing so hard and why are we still working on it? We’ve identified plenty of barriers and worked to address them. In many cases, we’ve addressed them quite well. For example, information sharing is tough from a technical perspective because the volume and speed of data continues to increase. So the community developed standards like STIX (Structured Threat Information eXchange) as a common language to share indicators and context at machine speed, TAXII (Trusted Automated eXchange of Intelligence Information) to provide a protocol for the transfer of information, and MITRE’s ATT&CK framework for […]

The post Trust us, information sharing can work. Here’s how we’re doing it. appeared first on CyberScoop.

Continue reading Trust us, information sharing can work. Here’s how we’re doing it.

Software vulnerability disclosures by NSA will continue under Trump, officials say

The disclosure process that governs how and when federal agencies should tell tech firms about flawed computer code is in no immediate danger of termination under the Trump administration, current and former U.S. officials said. Flawed code by its very nature offers vulnerabilities that can be targeted by hackers. Knowledge of these vulnerabilities — especially those […]

The post Software vulnerability disclosures by NSA will continue under Trump, officials say appeared first on Cyberscoop.

Continue reading Software vulnerability disclosures by NSA will continue under Trump, officials say