Vulnerability Management

Submodule 1 (3 sessions)

Session 1: Vulnerability Management Process & Standards

The task of dealing with Vulnerabilities in Software, and sometimes even in Hardware, has gone from an ad hoc, emergency activity to a continuous, planned task that has become one of the building blocks of reliable, secure systems and networks.

This webinar will give an overview of the existing standards and will cover some of the key elements, like CVE and CVSS, in depth, that will be referenced throughout the coming webinars on vulnerability management. 

session 1 recording

session 1 presentation

Session 2: Vulnerability Information – How to gather and distribute security advisories to your constituency

Before one can address with vulnerabilities, one needs to be aware of them: their existence, their consequences, and what to do about them. While CSIRTs and PSIRTs take care of the initial steps in researching and publishing information, the task of actually forwarding this information to the administrators responsible for vulnerable systems, is something that every organisation has to deal with themselves.

This webinar will show how this task can be dealt with and what information should be included in a security advisory. 

session 2 recording

session 2 presentation

Session 3: Patch Management – How to roll out and track security fixes to your systems

Patching' is the name given to the process of replacing vulnerable software with a corrected version. However, the sheer number of patches that has to be applied constantly has led to the requirement to automate and track the application of patches.

This webinar will give an overview of the process of applying patches and what tools can be used to automate the task. 

session 3 recording

session 3 presentation

Submodule 2 (3 sessions)

Session 1: Looking into the network – how to scan local systems for vulnerabilities and misconfigurations

Today's systems are so complex that it's almost impossible to run a system without vulnerabilities and misconfigurations. And although there are plenty of benchmarks, baselines, and hardening guides available, it is difficult to apply them to the local environment.

This webinar will introduce some of the most useful frameworks and tools for local vulnerability scanning. 

session 1 recording

session 1 presentation

Session 2: Network Vulnerability Scanning – Looking from Afar

In order to stay ahead of the threats to a large infrastructure, it is crucial to maintain a clear picture of whether there are vulnerabilities in the components deployed and, if so, which ones. Scanning systems through the network is one way of gaining insight into this issue.

This webinar will provide an introduction to the concepts of network scanning, its benefits, and its drawbacks, as well as offer some practical examples. 

session 2 recording

session 2 presentation

Session 3: Penetration tests – how does your network stand up against real attacks?

No matter how much scanning for vulnerabilities and security process evaluating is done, one question remains: is this really enough against real attacks? Short of experiencing an attack in real life, penetration tests try to answer this question by conducting attacks in a controlled manner.

This webinar will give managers and administrators an introduction to the standards and workflow of penetration tests to help in planning and supervising penetration tests carried out on their networks.

session 3 recording

session 3 presentation

Submodule 3 (3 sessions)

Session 1: Code Audits

Software without bugs or vulnerabilities doesn't exist. If your organization runs software development teams they will likely have heard of things like secure software development lifecycles and the like.

This webinar will introduce some basic concepts as well as tools that help developers finding bugs before the software goes into production.

session 1 recording

session 1 presentation

Session 2: Vulnerability disclosure

So you have found vulnerabilities in other people's code. Or other people have found vulnerabilities in your code. Either way: How to handle the situation? In the long run, trying to keep information about the vulnerability under wraps is unlikely to work.

In this module, we will cover some aspects and strategies of how to approach this issue. 

session 2 recording

session 2 presentation

Session 3: Breach and attack simulation – matching attacker behaviour with vulnerabilities

Breach and Attack Simulation (BAS) is a relatively new approach to vulnerability assessment that goes beyond simple scoring of vulnerabilities by also taking the modus operandi of adversaries into account.

This webinar will give an introduction into the topic and present some open source tools to do BAS. 

session 3 recording

session 3 presentation