EJ Feng
EJ Feng
Senior Cybersecurity Engineer
Moxa

Senior Cybersecurity Engineer in Moxa Product Security Center, mainly responsible for Moxa PSIRT and CNA vulnerability handling processes. Assisted Moxa in becoming the 8th CVE Numbering Authority (CNA) in Taiwan.

SPEECH
5/15 (Wed.) 14:45 - 15:15 7F 702 Product Security Forum
How Close We Are to Vulnerability Management - Joining the CNA Program and Practical Experience in Handling PSIRT Vulnerability Incidents

Even if IEC 62443 provides a process maturity level, how can we gradually move closer to the overall qualified standard in the face of different generations of products within the enterprise and the characteristics of the product life cycle in OT field.

This session shares how we use the activities of the Product Security Incident Response Team (PSIRT) as feedback to SSDLC. Use vulnerability handling activities to review the product process from requirements, design, implementation, testing and verification to make the process more mature and complete.