CY Lai
CY Lai
Lead Cybersecurity Engineer
Moxa

Having experienced various roles including telecommunications system engineer, PoC tool developer, product manager, and cybersecurity consultant, I currently work at Moxa's Product Security Center. Together with Moxa, I am writing a memoir on achieving cybersecurity.

SPEECH
5/15 (Wed.) 14:45 - 15:15 7F 702 Product Security Forum
How Close We Are to Vulnerability Management - Joining the CNA Program and Practical Experience in Handling PSIRT Vulnerability Incidents

Even if IEC 62443 provides a process maturity level, how can we gradually move closer to the overall qualified standard in the face of different generations of products within the enterprise and the characteristics of the product life cycle in OT field.

This session shares how we use the activities of the Product Security Incident Response Team (PSIRT) as feedback to SSDLC. Use vulnerability handling activities to review the product process from requirements, design, implementation, testing and verification to make the process more mature and complete.