Theater #2: CISA’s Vulnerability Management: Contributions to the Global Cybersecurity Ecosystem

  • Room: Theater #2 - Booth 2300
Tuesday, May 06, 2025: 2:45 PM - 3:45 PM

Speaker(s)

Speaker (confirmed)
Paul Brandau
Chief, Red Team Capabilities
Cybersecurity and Infrastructure Security Agency
Speaker (confirmed)
Kevin Donovan
Deputy Chief, Vulnerability Response and Coordination
Cybersecurity and Infrastructure Security Agency
Speaker (confirmed)
Martin Kihiko
Deputy Chief, Cyber Resilience
Cybersecurity and Infrastructure Security Agency
Speaker (confirmed)
Sean Letona
Chief of Operations, Vulnerability Management
Cybersecurity and Infrastructure Security Agency (CISA)
Speaker (confirmed)
Victoria Ontiveros
Program Manager, Software Bill of Materials (SBOM) and Open Source Software (OSS) Security
Cybersecurity and Infrastructure Security Agency
Speaker (confirmed)
Sandy Radesky
Associate Director, Vulnerability Management
Cybersecurity and Infrastructure Security Agency

Description

CISA Vulnerability Management performs critical functions that are valued by the broader cybersecurity ecosystem. In this panel, we’ll talk about our role in the CVE program, driving toward complete, accurate and timely CVEs with root cause analysis through CWEs. We’ll highlight our Known Exploited Vulnerabilities (KEV) and the importance of our the high bar we set.  We’ll cover the latest with our SBOM program and trajectory it’s on in the federal government, industry and internationally. CISA VM will have representatives from the CISA Red team, High Value Asset and Validated Architecture Design Review assessments teams to talk about the scope and scale of special authorities, that enable us to truly test our stakeholders.  The team will cover the difference in our IT vs. OT assessments and share the intent behind future plans which aim focus on on Zero Trust and software security.

Listen Here


Tracks: