Opensource Software Security in the DoD
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Open source software promises cost savings and faster innovation, but the Department of Defense's approach to it is messier than most people realize. Host Matt Triner sits down with Hunter Strategy's Greg Vanore (Director of Software Engineering) and Nate Kingsley (CIO) to unpack the real risks: contributor license agreements that can sign away government-funded code, foreign ownership questions that don't always get consistent answers, and a supply chain that's only as trustworthy as its weakest link. They also dig into what's actually fixing the problem, from CI/CD pipelines to continuous ATO. This one gets spicy.Episode Chapters:
00:00 Introduction and Overview
01:59 Defining Open Source Software
03:49 Contributor License Agreements and Licensing Issues
06:08 The Challenges of Open Source Software in the DoD
08:39 The Need for Clear Policies
11:25 The Financial Challenges of Open Source Software
17:19 The Risk of Support and Lack of Governance
20:12 The Permissiveness of Open Source Software in the DoD
24:02 Supply Chain Risk and Software Sourcing
30:11 Improving the Use of Open Source Software
35:16 The Role of S-BOMs and Information Sharing
37:49 Conclusion and Call to Action