CISO们对SolarWinds攻击的看法
时间:2022-04-15 18:27:01 | 来源:行业动态
时间:2022-04-15 18:27:01 来源:行业动态
Last year, right after the attack, friend of theCUBE Val Bercovici of Chainkit said to us on Twitter that he thinks the government hack will have permanent implications on how organizations approach cybersecurity. CISOs seem to agree. Here are some verbatim comments from the CISO roundtable moderated by ETR in late January:
去年我们的CUBE朋友 Val Bercovici of Chainkit在攻击发生后发给我们的推特消息表示,他认为政府被黑将对以后组织如何对待网络安全产生永久性影响。CISO们似乎都同意这个观点。以下是1月底由ETR主持的CISO圆桌会议上的一些评论原文。
The impact of the breach is profound. It really turned on its head a lot of conventions about cybersecurity. I dont think the threat has been exaggerated in the media.
- 这次泄露的影响是深远的,真的颠覆了很多关于网络安全的惯例,我不认为媒体夸大了威胁。
- Were now in a situation where we have to monitor the monitors.我们现在所处的情况是,我们必须监控那些监控机构。
- This attack didnt have any signatures of a previous attack so you got down to the code level.这次攻击不具有任何过去攻击的特征所以是到了代码层面。
- 80-90% of that code is being downloaded from the internet. Its bringing DevOps security processes and making us rethink how to reinvent security.那些代码的 80-90%都是从网上下载的。事关DevOps安全流程,我们得重新思考如何重塑安全。
### What can be done?