OCP S.A.F.E. Update.pdf

編號:161451 PDF 9頁 930.81KB 下載積分:VIP專享
下載報告請您先登錄!

OCP S.A.F.E. Update.pdf

1、A brief update on the S.A.F.E initiative since launch in October 2023 followed by a panel discussion.OCP S.A.F.E UpdateEric Eilertson,Security Architect,MicrosoftAlex Tzonkov,Security Architect,AMDAlfredo Pironti,Director,IO ActiveOCP S.A.F.E UpdateSecurity and Data ProtectionSECURITYStandardize Sec

2、urity Reviews from CSPs and hyperscalersRemove need for multi-party NDAsMove security reviews earlier into the development lifecycleEngage SRP early and oftenThe final review could be largely ceremonialSecurity Reviews become standard rhythm of businessS.A.F.E OverviewScope 1 Secure boot+FirmwarePro

3、per handling of critical security parametersInput validationMemory safetyStorage DevicesValidation of crypto erase and block overwriteScope 2 Designed for isolationROT/Security processor and memory isolated from application coresApplication cores and firmware provide isolation between processesScope

4、 3 Designed to withstand physical attacksArchitecture has mitigations for glitch and side channel attacksReview AreasTechnical Advisory CommitteeThordur Bjornsson GoogleEric Eilertson MicrosoftTim Pletcher HPEMichael Schneider IDA/CCSTAC will evaluate Security Review Provider applicationsTAC will ma

5、nage the framework,review areas,SRP criteriaSRP list from October 2023 LaunchAtredis,IO Active,NCC GroupTetrel Security added March 2024S.A.F.E.Programmatic UpdateUpcoming LegistationNational-Cybersecurity-Strategy-2023.pdf(whitehouse.gov)Outlines administrations proposed strategy to address emergin

6、g cybersecurity threats.Section 3.3:shift liability for insecure software products and services.https:/www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdfCTO of software provider is accountable for software delivered.European Commission Cyber Resilience ActCyber Resilience

7、Act|Shaping Europes digital future(europa.eu)Proposes Cyber security conformance assessments.Penalties for non-conformancePotential Challenge:Recurring audits impact device costs and schedulesEarly Adopters Experience with S.A.F.E.OCP Value Prop for AMD as Device Vendor:Before OCP S.A.F.E.:Multiple

8、custom audits for the same deviceSimilar audit outcomes,multiple customer dialogsWith OCP S.A.F.E.:S.A.F.E.audit scope,eliminates multiple audits&dialogs Enhances security transparency via Short Form Report(SFR)S.A.F.E.audit scope levels integrate well with AMDs SDLCall to ActionDevice VendorLook ov

9、er the security review areas and prepare for your first security reviewIs your preferred security review firm endorsed as a S.A.F.E.review provider?If not encourage them to apply!Security Review ProviderLook over the review areas,is there anything missing?Apply to become a S.A.F.E.review providerhttps:/www.opencompute.org/projects/ocp-safe-programhttps:/ Discussion

友情提示

1、下載報告失敗解決辦法
2、PDF文件下載后,可能會被瀏覽器默認打開,此種情況可以點擊瀏覽器菜單,保存網頁到桌面,就可以正常下載了。
3、本站不支持迅雷下載,請使用電腦自帶的IE瀏覽器,或者360瀏覽器、谷歌瀏覽器下載即可。
4、本站報告下載后的文檔和圖紙-無水印,預覽文檔經過壓縮,下載后原文更清晰。

本文(OCP S.A.F.E. Update.pdf)為本站 (張5G) 主動上傳,三個皮匠報告文庫僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對上載內容本身不做任何修改或編輯。 若此文所含內容侵犯了您的版權或隱私,請立即通知三個皮匠報告文庫(點擊聯系客服),我們立即給予刪除!

溫馨提示:如果因為網速或其他原因下載失敗請重新下載,重復下載不扣分。
客服
商務合作
小程序
服務號
折疊
午夜网日韩中文字幕,日韩Av中文字幕久久,亚洲中文字幕在线一区二区,最新中文字幕在线视频网站