Loading…
Thursday, April 18 • 4:00pm - 4:45pm
What’s Oracle Doing to Secure its Products? (P104)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

The public face of Oracle’s product security is its quarterly security patches or Critical Patch Updates and the occasional Security Alert that fix vulnerabilities that are being actively exploited “in the wild”.  As well as reviewing Oracle's product vulnerability handling practices, this presentation will explain the core elements and challenges of the less public but broader and more important Oracle Software Security Assurance program including:

  • Secure development processes and practices, and the foundation on which they're built, Oracle's Secure Coding and Development Standards that include lessons learned from past experiences
  • Comprehensive security analysis and testing
  • Secure configurations with guides and utilities to identify deviation from known secure states
  • Independent product security testing evaluations and validations
  • Building a decentralised, delegated, internal security community
  • Applying security bar-raising changes
  • Introducing cultural and process change to new product acquisitions

 


Foredragsholdere
avatar for Duncan Harris

Duncan Harris

Senior Director of Security Assurance, Oracle
Duncan Harris is senior director of security assurance at Oracle, responsible for all productsecurity vulnerability handling, for Oracle's internal ethical hacking team, for formal productsecurity evaluations such as Common Criteria and FIPS 140, and for defining, educating,evangelising... Read More →


Thursday April 18, 2013 4:00pm - 4:45pm CEST
3. Bundestag Color Magic