10–14 Oct 2016
San Francisco Marriott Marquis
America/Los_Angeles timezone

Internal security consulting, reviews and penetration testing at CERN

13 Oct 2016, 11:15
15m
Sierra C (San Francisco Mariott Marquis)

Sierra C

San Francisco Mariott Marquis

Oral Track 8: Security, Policy and Outreach Track 8: Security, Policy and Outreach

Speaker

Sebastian Lopienski (CERN)

Description

The CERN Computer Security Team is assisting teams and individuals at CERN who want to address security concerns related to their computing endeavours. For projects in the early stages, we help incorporate security in system architecture and design. For software that is already implemented, we do penetration testing. For particularly sensitive components, we perform code reviews. Finally, for everyone undertaking threat modelling or risk assessment, we provide input and expertise. After several years of these internal security consulting efforts, it seems a good moment to analyse experiences, recognise patterns and draw some conclusions. Additionally, it's worth mentioning two offspring activities that emerged in the last year or so: White Hat training, and the IT Consulting service.

Primary Keyword (Mandatory) Security and policies
Secondary Keyword (Optional) Software development process and tools

Primary author

Presentation materials