当前位置:首页 > 报告详情

OCP S.A.F.E. Update.pdf

上传人: 张** 编号:161451 2024-05-05 9页 930.81KB

1、A brief update on the S.A.F.E initiative since launch in October 2023 followed by a panel discussion.OCP S.A.F.E UpdateEric Eilertson,Security Architect,MicrosoftAlex Tzonkov,Security Architect,AMDAlfredo Pironti,Director,IO ActiveOCP S.A.F.E UpdateSecurity and Data ProtectionSECURITYStandardize Sec

2、urity Reviews from CSPs and hyperscalersRemove need for multi-party NDAsMove security reviews earlier into the development lifecycleEngage SRP early and oftenThe final review could be largely ceremonialSecurity Reviews become standard rhythm of businessS.A.F.E OverviewScope 1 Secure boot+FirmwarePro

3、per handling of critical security parametersInput validationMemory safetyStorage DevicesValidation of crypto erase and block overwriteScope 2 Designed for isolationROT/Security processor and memory isolated from application coresApplication cores and firmware provide isolation between processesScope

4、 3 Designed to withstand physical attacksArchitecture has mitigations for glitch and side channel attacksReview AreasTechnical Advisory CommitteeThordur Bjornsson GoogleEric Eilertson MicrosoftTim Pletcher HPEMichael Schneider IDA/CCSTAC will evaluate Security Review Provider applicationsTAC will ma

5、nage the framework,review areas,SRP criteriaSRP list from October 2023 LaunchAtredis,IO Active,NCC GroupTetrel Security added March 2024S.A.F.E.Programmatic UpdateUpcoming LegistationNational-Cybersecurity-Strategy-2023.pdf(whitehouse.gov)Outlines administrations proposed strategy to address emergin

6、g cybersecurity threats.Section 3.3:shift liability for insecure software products and services.https:/www.whitehouse.gov/wp-content/uploads/2024/02/Final-ONCD-Technical-Report.pdfCTO of software provider is accountable for software delivered.European Commissi

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文是对开放计算项目(OCP)安全审计和评估框架(S.A.F.E)的更新。S.A.F.E自2023年10月启动以来,通过标准化安全审查、消除多方NDA需求、将安全审查提前至开发周期早期等措施,提高了安全与数据保护标准。审查范围分为三部分:1. 启动和固件的安全;2. 设计用于隔离的架构;3. 设计以抵御物理攻击。技术咨询委员会(TAC)负责评估安全审查提供商,并管理审查区域和SRP标准。从2023年10月启动以来,SRP包括Atredis、IO Active和NCC Group,Tetrel Security于2024年3月加入。未来立法和政策,如美国的《2023年国家网络安全战略》和欧盟的《网络弹性法案》,可能将安全责任转移到软件提供商。OCP S.A.F.E.通过整合审计和提高安全透明度,为AMD等设备供应商提供了价值。最后,文章呼吁设备供应商审查安全审查领域并准备首次审查,同时鼓励安全审查提供商申请成为S.A.F.E.审查提供者。
"S.A.F.E. 安全审查有哪些范围?" "如何成为OCP S.A.F.E.安全审查提供者?" "S.A.F.E. 计划对设备供应商和审查机构意味着什么?"
客服
商务合作
小程序
服务号
折叠