Loading…
Attending this event?
October 22-23, 2024 | Atlanta, Georgia USA
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for SOSS Fusion 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Saving Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Wednesday October 23, 2024 10:35am - 11:05am EDT
The US Department of Defense, like many industrial, academic, and government institutions across the world, are intricately dependent on open source software and seek concrete means to objectively assess the trustworthiness of not only the products of the OSS ecosystem but also the processes enacted by projects to produce that software. One such DoD project, Unified Platform, is developing techniques to evaluate publicly available information from OSS projects to determine the risk levels associated with using the open source software, both now and in the future. Current efforts are concentrating on evaluating a project’s processes, policies, and practices. This includes leveraging tools such as MITRE’s Hipcheck, the Open Source Security Foundation’s Scorecard, and other sources to support Unified Platform's Software Approval Process and Software Supply Chain Practices. This presentation will cover how these techniques are providing the insight needed by this DoD project to address emerging DoD guidance in the use of open source software.
Speakers
avatar for Joshua Crisp

Joshua Crisp

Chief Information Security Officer, Unified Platform (USCYBERCOM)
Unified Platform Chief Information Security Officer supporting USCYBERCOM and JCWA. I've spent a little over 5 years supporting Unified Platform capabilities for cybersecurity, cloud infrastructure, cybersecurity for Air Force's Platform One program (IronBank, BigBang, PartyBus... Read More →
avatar for Scott Hissam

Scott Hissam

Senior Member of the Technical Staff, Carnegie Mellon Software Engineering Institute
Based in San Antonio, TX where I manage and coordinate local staff and technical activities in support of and DoD organizations. I am also a technical lead/program manager, leading research to practice in software engineer and software technology for acquisition and sustainment of... Read More →
Wednesday October 23, 2024 10:35am - 11:05am EDT
Salon 1

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link