当前位置:首页 > 报告详情

6510 - OCP S.A.F.E. Update and The Five Most Asked Questions.pdf

上传人: 芦苇 编号:651466 2025-05-01 15页 890.53KB

1、Eric Eilertson,MicrosoftNick Hummel,GoogleIlja van Sprundel,IOActiveOCP S.A.F.E.UpdateOCP S.A.F.E.UpdateEric Eilertson,MicrosoftNick Hummel,GoogleIlja van Sprundel,IOActiveSecuritySpeaker introductionAbout S.A.F.E.Introduction to the programCurrent statusAdvice from a SRPCost considerationsThings to

2、 knowPreview of structural changesAgendaSpeakersEric EilertsonMicrosoftS.A.F.E.LeadNick HummelGoogleS.A.F.E.LeadIlja van SprundelIOActiveS.A.F.E.SRPAbout S.A.F.E.Security Appraisal Framework and EnablementSRP BEach customer wishing to purchase a device needs to find and vet a suitable security revie

3、w providerDevice vendors needs to collaborate with several independent SRPs/customers providing duplicate informationCollaborating with small customers is not worth the effort for vendorsTraditional modelVendorCustomer ACustomer CCustomer BSRP ASRP CS.A.F.E.standardizes security audits of HW/FW,espe

4、cially datacenter server components,like CPUs,GPUs,SSDs,NICsCustomers share one review,saving costsVendors only need to work with one SRP,saving effortVendors are incentivized to provide high quality continuous reviews as there are many customersNew model under OCP S.A.F.E.VendorCustomer ACustomer C

5、Customer BSRPPrograms such as FIPS and Common Criteria provide specific checklists of things that need to be fulfilledThis leads to focus on ticking boxes rather than holistically considering securityS.A.F.E.instead focuses on strictly vetting high quality SRPs that are then given sufficient freedom

6、 to assess security comprehensivelyDifference to certification programs8 approved Security Review ProvidersMicrosoft requires S.A.F.E.audits for all security-relevant server componentsGoogle requires security audits for all security-critical server components;if conducted externa

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了OCP S.A.F.E. Update的安全评审框架和实施计划。在新的模型下,客户和设备供应商通过与单一的安全评审提供者(SRP)合作,共享评审结果,从而节省成本和努力。文章指出,传统的模型中,供应商需要与多个SRP合作,提供重复的信息,而OCP S.A.F.E.的新模型则简化了这个过程。同时,文章也提到了一些关键的数据,如微软和谷歌都要求其安全相关的服务器组件进行S.A.F.E.审计,目前已经有8家安全评审提供商获得了批准。此外,文章还提供了一些建议,如从白盒评估开始,然后进行差异评估,以及一些成本和流程方面的考虑。最后,文章鼓励大家参与到S.A.F.E.的实施中来,并提供了相关资料的链接。
有何亮点?" "如何通过S.A.F.E.减少安全审计成本?" "成为Security Review Provider,有何要求?"
客服
商务合作
小程序
服务号
折叠