Главная
Study mode:
on
1
Intro
2
Certifications
3
Good Standards
4
Product Security Advisory
5
SelfService Portal
6
Timeline
7
Customer Report
8
Vulnerability triage
9
Pizza
10
Patching
11
Interim release
12
User personas
13
Garys needs
14
No evidence
15
False positives
16
Customer remediation
17
Testing qualification
18
Vulnerability disclosure playbook
19
Internal communications
20
Timing
21
Customer feedback
22
The right amount of time and effort
23
Summary
24
Conclusion
25
Questions
Description:
Explore the critical role of empathy in vulnerability disclosure practices for software vendors in this 46-minute LASCON conference talk. Delve into the complexities of security advisories beyond standard templates and process maps, examining how decisions around information sharing, audience understanding, and customer support reflect team values. Learn from a real-world product security advisory case study, including cross-functional team collaboration and decision-making processes. Gain insights into successful practices, lessons learned, and recommendations for future security advisories and response strategies. Discover how empathy can preserve trust and enhance vulnerability disclosure processes, even though it's not explicitly mentioned in ISO 29147 standards.

The Role of Empathy in Vulnerability Disclosure Practices for Software Vendors - 2017

LASCON
Add to list