Bob Martin, MITRE | RSA Conference 2022
Transcript
So this is texturong TV. Hey everyone. We're back here live again.
Thursday morning Moscone West RSA conference the escalators of film with people going up and down and down and up sessions are on Keynotes are starting. We're wrapping up our last day of our it's a today. I'm really happy to be joined with someone who I've been interviewing.
And RSA for a really long time decades a couple of decades actually before we even were interviewing him. Well back in my Social Security days. Of course, we had a vulnerability solution vulnerable van vulnerably early access management.
and back, then the whole game-changer in the vulnerabilities management space was the Advent of the cve's yep, right from the minor Corp where they started raining vulnerabilities by severity and criticality Etc. And it was about 15 now more 18. Well, they started rolling out in the fall of 1999.
What did you present here? That was 2001. So this is when I first met this red, his name's Bob Martin, he's with minor in 2001 Bob stood up on stage here at RSA and introduced the whole concept of CVS for vulnerability management and the world of vulnerability management has never been the same here.
We are two decades later. 2022. Bob is up on stage this year where he About supply chain security and you know, I have a feeling supply chain security may not be the same again.
Yeah, it's from your lips to God's ears right? I hear you about so welcome Frizzle Bob. Welcome well and ready here glad to see everyone.
Yep. It's really a lot of connections and and new people too and it is good to see the new people but you know, what? If no one's told you here this year.
I'll tell you thank you. Thank you for all that. You've done over the last decades.
Well, I take that. Thanks now spread it across the big team. Yeah it is, you know in miter and in the community and that's the key to these kinds of things it is it takes a team.
Yeah, it takes a community and well and it has to also not just be some technically neat way of doing something that's making business. Yes, and that's I think a big part of this and that's where our And what we call a system of Trust on supply chain, really we think is going to be something that industry is going to find as much or more value than miter's customers in the federal government, you know miter is a not-for-profit we run what are called federally funded research and development centers for many parts of the federal government in the US, but our mission is really to go out and change the problem space into something a little more tractable. Yep agreed.
So well, I think most of our audiences they've heard minor and our little definition there. I think helps out. Let's talk supply chain what you know talk about your your talk here.
Why not us everybody else is talking about. Yes that that appears to be for sure. Yeah.
Now the the whole approach we're taking on supply chain is that there are experts in supply chain, but then there's everyone else that's really struggling to get a grip on it and trying to understand what are the risks they need to understand get a handle on and look into and there's really no place that they can look to to understand and appreciate what they may need to look at. So what system of trust primarily is trying to do or at least the first step is what are all those supply chain risks from your supplier the service offerings and supplies that you may need. To address now, we're not going to say everybody needs to do all that.
Right? So the other step of this is a way of managing to slim down to some set. We call it a profile that's appropriate to the business decision.
You're making your situation your context your timeline. And so you basically start with the common place and get to a precise place for you. Yet it's traceable back to that.
Yes, I pulled it from here. So as the community helps us make sure that bigger picture is full and Rich with specifics. You can still get down to something that makes sense and it fits your needs constraints.
And so that profile then is what you would go and do an assessment again, and we actually are going to be offering a scoring mechanism inside there really but one that can be adjusted because what you think of as a risk, I may say we're learning from the whole cve. Oh, yeah. No, we need to get those two together.
And we also want to make sure that when you get down to those specific risks, some people may not know what how do I get a handle on that risk? What do I look at? Where do I get data about it?
Do I need to do some kind of a test? Do I need to go look at some data source. So we're gonna be giving as much guidance as we can as to where to go get things that may be just general research and a specific area or maybe go to a specific vendor that offers that kind of information or some public.
Website that offers that but there's going to be a lot of it where you actually have to dig in and do something especially if you get into, you know, small non publicly traded companies you may have to do a questionnaire but there's some work that the DHS ICT scrum task force did on a common vendor questionnaire. So we're looking to make that machine consumable so you could distribute get it back. We can bring the answers in to System of trust as a starting point.
Wow. So there's a whole bunch of things here. We're really hoping that as well thought out but those who says like there's still a lot more to come there is we really need the community both vendors people who have Supply chains because we all you know in Supply chains.
Yeah, very, you know, you're you're consumer of some things but your supplier of others and also there's a lot of Situations, you know in Industry that have regulations they have to follow government. They have their rules. So all these things we need to figure out how to factor them in and it's like CV like cwe like sticks taxi the attack framework.
We need the contributions so that this really meets the need of the community. And so one of the things we're doing here, we have a public website. org.
It's out there to start. It's going to be flushed out. But we really look forward to people getting engaged on this.
Well look. If there's a if there's a right organization to lead this sort of effort, I can't think of a better one than miter. Well, I appreciate that.
Yep. You know. We had our devsecops event.
Tuesday and of course, you know supply chain security is on everyone's lips here and I serve very chancy wine. Probably no changes. Had very interesting take about an aspect of software of supply chain security that perhaps we haven't thought about and that was the whole IP issue.
Yeah right in our rush to to be transparent. about our supply chains Do we need to think about? Making them so easily accessible well, so that's a big misnomer I think in many so I think you're getting into the whole software Bill material and how you make that available and and transparent.
It's doesn't freeclude you from protecting your intellectual property. Okay. So the idea of an s-bomb is can you articulate what's in your software?
Not that can you put it on a public website somewhere. So the idea is one. Can you get it can be machine consumable?
Can you include Providence pedigree some Integrity information, but it's a starting point. It's a critical one, but you know, most of the customers are going to want other things. They're going to know what testing was done.
How is the development done? So there's going to be other things you need to get into that and I think if you look at the executive order 14028 that came out last year. It actually said well, yes, you need an s bomb if you're gonna sell to the federal government.
Doesn't say it needs to be some public place but it also asks for claims against what you did building that software that you have the s-bomb for and so that's another big part and I actually talked about that as part of my you talk in that there's some efforts project called Salsa in the ietf which is a language in a way of talking about those claims. But another part of that is coming out of the ietf and Linux Foundation. It's basically called supply chain Integrity transparency and trust and so, you know, it's basically the idea of you know some way of capturing maybe in a ledger these kinds of claims.
So an s bomb is a plane. Yeah. So are all these other things you may want to State.
Well, you can also as an organization say I have a policy that You know if I'm developing software software doesn't go from here to here until certain things are done. And so you could use this ledger to actually gate and control how things flow. There's a project in Linux foundation called in Toto that does that a little differently, but the idea is Keep track of what's going on and also know what should have been going on, right?
But the final part of this is that's the manufacturing of software. Then you step back and say okay now there's the marketplace of software, right? So somebody's creating this Ledger entries putting all these statements and third-party and first party.
I'm an Enterprise. I can have a policy about what kinds of attestation what claims and evidence I need for things to come in. And I can go put that on The Ledger too, and then I have a guard function right?
And so when a user at my company says I want some software. The guards, you know, the request goes out you pull our policy and they have stationed claims and stuff and see if they match. Okay, you can come in now.
So I think there's some interesting way. No, they're absolutely yes, you know it. I I love the ability to to customize that that user level.
Yeah. Well because not one size doesn't fit always over and over some people are very adventurous. Some people are conservative.
Yeah, that's what makes the world go around right Bob. I want to thank you for stopping in. Oh, you're treasure man.
Hope to see your next year and then maybe in some other events, but keep up the great work appreciate that. Take care. org.
Perfect. Thank you. All right.
We're live here at RSA. We're going to be back with our next guest in just a moment.

