Zero trust is poorly named and an oxymoron (my paraphrase) - it’s really about moving from today’s “gratuitous trust” to “reasonable trust” based on what you can verify. Ron Dilley and Johannes Jaskolski at #ATTSecCon.
Teamwork on cyber defense at #ATTSecCon using a pretend incident. Well done Cindy Cama, @JohnHogoboom, Stan Nurilov, Manny Ortiz, and Tony Tortorici for the “real” incident that occurred during your talk.
Besides mentioning US National Cybersecurity Strategy at #ATTSecCon, @ritamarty also mentioned EO 14028 and how useful #SBOM is reducing reaction time from days/weeks to hours.
Worth reading IMHO. I particularly liked "No More Unaccountability Through Obscurity".
"Who’s Afraid of the SEC?" https://t.co/5MuHxw7KsP via @AtlanticCouncil