CISO們對SolarWinds攻擊的看法
時間:2022-04-15 18:27:01 | 來源:行業(yè)動態(tài)
時間:2022-04-15 18:27:01 來源:行業(yè)動態(tài)
Last year, right after the attack, friend of theCUBE Val Bercovici of Chainkit said to us on Twitter that he thinks the government hack will have permanent implications on how organizations approach cybersecurity. CISOs seem to agree. Here are some verbatim comments from the CISO roundtable moderated by ETR in late January:
去年我們的CUBE朋友 Val Bercovici of Chainkit在攻擊發(fā)生后發(fā)給我們的推特消息表示,他認(rèn)為政府被黑將對以后組織如何對待網(wǎng)絡(luò)安全產(chǎn)生永久性影響。CISO們似乎都同意這個觀點(diǎn)。以下是1月底由ETR主持的CISO圓桌會議上的一些評論原文。
The impact of the breach is profound. It really turned on its head a lot of conventions about cybersecurity. I dont think the threat has been exaggerated in the media.
- 這次泄露的影響是深遠(yuǎn)的,真的顛覆了很多關(guān)于網(wǎng)絡(luò)安全的慣例,我不認(rèn)為媒體夸大了威脅。
- Were now in a situation where we have to monitor the monitors.我們現(xiàn)在所處的情況是,我們必須監(jiān)控那些監(jiān)控機(jī)構(gòu)。
- This attack didnt have any signatures of a previous attack so you got down to the code level.這次攻擊不具有任何過去攻擊的特征所以是到了代碼層面。
- 80-90% of that code is being downloaded from the internet. Its bringing DevOps security processes and making us rethink how to reinvent security.那些代碼的 80-90%都是從網(wǎng)上下載的。事關(guān)DevOps安全流程,我們得重新思考如何重塑安全。
### What can be done?