25 subscribers
Pergi ke luar talian dengan aplikasi Player FM !
Podcast Berbaloi untuk Didengar
DITAJA


1 How To Replace A $100,000+ Salary Within 6 MONTHS Through Buying A Small Business w/ Alex Kamenca & Carley Mitus 57:50
Securing the Software Supply Chain with Chip Childers, VP Security at VMware and Jim Mercer, VP DevSecOps at IDC
Manage episode 380825340 series 2623537
Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.
Key Quotes:
“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip
“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim
---------
Timestamps:
(01:15) Why are we concerned about the software supply chain?
(05:25) Building complex systems on top of other complex systems
(08:15) Realizations from the Log4j incident
(11:22) Resulting shifts from new compliance and regulations
(16:21) Creative chaos in the software industry
(18:48) Reliance on the open-source community
(19:23) How can you identify where code is coming from?
(20:17) Prioritizing vulnerabilities
(23:08) The snowball effect in the supply chain
(25:00) How do you understand your exposure?
(33:15) The impact of generative AI
(37:27) Where should CIOs start heading into board level conversations?
--------
Links:
Chip Childers on LinkedIn
Jim Mercer on LinkedIn
Yadin Porter de León on Twitter
[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio
73 episod
Manage episode 380825340 series 2623537
Incidents like the Log4j incident and new governmental regulations have forced tech leaders to examine the security of their software supply chain. Understanding the complexities of this is challenging; how can CIOs determine their exposure and prioritize their vulnerabilities? In this conversation, Yadin sits down with Chip Childers, VP Security, Compliance, Open-Source & Privacy Engineering & Chief Open Source Officer at VMware and Jim Mercer, Research Vice President - DevOps & DevSecOps at IDC, to discuss the software supply chain and how CIOs should think about it, in depth. They look at how we became so reliant on the open-source community and the impact of generative AI.
Key Quotes:
“When you talk about the idea of having to have development resources to do patching, it's those transitive dependencies, honestly, that you may not be able to patch because you're relying on other people's work. That's why understanding this complexity really matters.” - Chip
“I don't think a lot of organizations realize how dependent they are on this open source community as we've started to kind of grow out, develop applications and rely so heavily on open source.”- Jim
---------
Timestamps:
(01:15) Why are we concerned about the software supply chain?
(05:25) Building complex systems on top of other complex systems
(08:15) Realizations from the Log4j incident
(11:22) Resulting shifts from new compliance and regulations
(16:21) Creative chaos in the software industry
(18:48) Reliance on the open-source community
(19:23) How can you identify where code is coming from?
(20:17) Prioritizing vulnerabilities
(23:08) The snowball effect in the supply chain
(25:00) How do you understand your exposure?
(33:15) The impact of generative AI
(37:27) Where should CIOs start heading into board level conversations?
--------
Links:
Chip Childers on LinkedIn
Jim Mercer on LinkedIn
Yadin Porter de León on Twitter
[Subscribe to the Podcast]
On Apple Podcast
For more podcasts, video and in-depth research go to https://www.vmware.com/cio
73 episod
Semua episod
×
1 Moving Fast, Securely with Laura Bell Main, CEO of SafeStack 35:28

1 Advice to CIOs from a VC Investor with Yon Hardisty, Founder of HealthTek Incorporated 33:13

1 Preparing for the Spacefaring Economy with Elizebeth Varghese, Partner / Principal, Space Economy Acceleration Leader at Deloitte 32:51

1 What Makes a Sustainable Business? with Srini Koushik, President Technology, Sustainability, and AI at Rackspace 37:54

1 The Sustainable Data Center and the “AI Gold Rush” with Missy Young, CIO of Switch 28:54

1 How to Choose Your AI Partners with Suhail Nimji, VP/Head of Business Development, Corporate Development, and Partnerships at Jasper 37:28

1 Securing the Software Supply Chain with Chip Childers, VP Security at VMware and Jim Mercer, VP DevSecOps at IDC 44:57

1 Speaking with AI: A Real-Time Conversation with Pi, a Personal AI Assistant 17:54

1 The Current State of AI in the Enterprise 23:09

1 Customer Zero – App Modernization with Multi-Cloud 30:36

1 Data Challenges and AI Opportunities in Healthcare with Peter Shen, Head of Digital Health - North America at Siemens Healthineers 26:11

1 Cybersecurity and Economic Prosperity with Dmitri Alperovitch, Co-Founder and Chairman of Silverado Policy Accelerator 29:50

1 “Emerging-Emerging” Trends with Tim Crawford, CIO Strategic Advisor at AVOA 49:01

1 Data Democratization and the “Intelligence Era” with Trevor Schulze, CIO of Alteryx 33:53

1 Managing Talent: Finding, Retaining, Upskilling, and Reskilling - with Abhimanyu Saxena, Co-Founder of Scaler 36:25

1 Customer Zero – Multi-Cloud Transformation 13:12

1 Generative AI: What CIOs Need to Know - with Paul Roetzer, CEO of Marketing AI Institute 40:59

1 Customer Zero - Customer Experience and the Use of Data 15:59

1 Platform Engineering and the Developer Experience - with Rob Hirschfeld, CEO and Founder of RackN 38:13

1 Customer Zero - Business Model Transformation 15:17

1 The New Needs of the Workforce - with Saket Srivastava, CIO of Asana 28:58

1 The Enterprise Impact of New Technology - with Sanjay Srivastava, Chief Digital Strategist at Genpact 46:40

1 Supercloud 23 - Applications & Developer Impact - Speakers: theCUBE hosts Dave Vellante and John Furrier, with Vittorio Viarengo, VP of Cross Cloud at VMware, and Sarbjeet Johal, industry influencer… 25:41

1 Building The Resilient Organization - with Dale Aultman, VP & GM of Infrastructure Solutions Group Services at Lenovo 33:05

1 Whose Responsibility is Secure Software? with Steve Lipner, Executive Director of Safe Code, and Karen Worstell, VMWare Cyber Strategist 30:55

1 The Future of Leadership - Guest: Michael Krigsman, industry analyst and publisher of CXOTalk 29:33

1 The Challenge of Cloud Compliance and Security - Guest: Hillery Hunter, GM and CTO at IBM Cloud 24:39

1 Supercloud 22 – “Supercloud” enablers and blockers - Speaker panel with theCUBE hosts, founder and CEO of Rafay Systems, CEO of Platform9 Systems and the CTO of VMware 16:00

1 Supercloud 22 – The multi-cloud roadmap and the gateway to “supercloud” - Speakers: theCUBE hosts Dave Vellante and John Furrier, with Kit Colbert, CTO of VMware. 21:26

1 Supercloud 22 – Securing the “supercloud” - Speaker panel with theCUBE hosts, CEO of Skyhigh Security, CEO of Accurics and the former Head of Product at VMware 17:48

1 Supercloud 22 – “Supercloud” – Real or hype? - Speaker panel with theCUBE hosts, Confluent CTO, Hashicorp CEO and the Cross Cloud VMware VP. 25:22

1 Supercloud 22 – What is the “supercloud” opportunity - Speakers: theCUBE hosts Dave Vellante and John Furrier, with Vittorio Viarengo, VP of Cross Cloud at VMware 17:39

1 Mindshifts for Modernizing Applications - Guest: Ginna Raahauge, CIO at Zayo 36:19

1 Managing Across Multiple Clouds and Taming the Chaos - Guests: Jeffrey Shaw, CIO and Dale Ramsey, VP of Cloud Infrastructure for Employers 17:36

1 Removing Silos: Why The Developer Experience Matters - Guest: Tihomir Bajic, CEO of LTSE Software 38:14

1 Innovating at the Speed of DevOps - Guest: Ashish Kakran, Principal of Thomvest Ventures 43:20

1 Having a Thick Skin in Executive Search is Critical - Guest: Martha Heller, CEO of Heller Search Associates 41:02

1 Investing One Step Ahead - Guest: Cindy Padnos, Founder & Managing Partner at Illuminate Ventures 33:39

1 Technology Solving the “Prosperity Paradox” - Guest: Wendy Gonzalez, CEO of Sama 24:24

1 CxO Conversations with Jason Conyard: The Relationship between CIOs and CSOs - Guest: Alex Tosheff, VP & CSO, VMware 26:15

1 Innovating Security, What Happens First? - Guests: Curt Carlson, Professor of Practice, Northeastern University and Distinguished Executive in Residence, WPI & Karen Worstell, Senior Cybersecurity… 37:04

1 Technology + Culture: How to Attract & Retain the Best Talent - Guests: Michael Loggins, Global VP of IT, SMC & Renu Upadhyay, VP, Product Marketing EUC, VMware 36:18

1 Does IT Innovation Have to be Disruptive? - Guest: Jason Conyard, CIO, VMware 34:11

1 Modernizing on Multi-Cloud - Guest: Rob Carter, EVP & CIO, FedEx 44:06
Selamat datang ke Player FM
Player FM mengimbas laman-laman web bagi podcast berkualiti tinggi untuk anda nikmati sekarang. Ia merupakan aplikasi podcast terbaik dan berfungsi untuk Android, iPhone, dan web. Daftar untuk melaraskan langganan merentasi peranti.