BEGIN:VCALENDAR
VERSION:2.0
PRODID:IEEE vTools.Events//EN
CALSCALE:GREGORIAN
BEGIN:VTIMEZONE
TZID:EST5EDT
BEGIN:DAYLIGHT
DTSTART:20220313T030000
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221106T010000
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20220525T041238Z
UID:36A552F3-AA53-4FCB-B962-5337B0D10B68
DTSTART;TZID=EST5EDT:20220523T190000
DTEND;TZID=EST5EDT:20220523T200000
DESCRIPTION:This meeting was recorded. You can view the meeting at https://
 youtu.be/W1CEtzhTJQ4.\n\nDid you have to deal with the Log4j or Spring4She
 ll vulnerability? How much time have you spent just tracking down whether 
 your company&#39;s software was affected by these problems? Do you even know w
 hat all of the components are that are included\, either directly or indir
 ectly\, in your software? How prepared are you for dealing with the next Z
 ero Day vulnerability?\n\nJoin us for this panel session to discuss the ro
 le of a [Software Bill of Materials](https://www.cisa.gov/sbom) as part of
  your software development process.\n\nPanelists include:\n\n- Allan Fried
 man - Leading CISA&#39;s efforts to coordinate SBOM efforts inside and outside
  the US Government and around the world.\n- L Jean Camp\, IEEE Fellow\, Pr
 ofessor of Informatics &amp; Computer Science. Center Director\, Security &amp; Pr
 ivacy in Informatics\, Computing\, &amp; Engineering at Indiana University (SP
 ICE)\n- Tom Alrich - Co-lead for the National Telecommunications and Infor
 mation Adminstration&#39;s Energy SBOM Proof of Concept. Consultant to electri
 c power industry clients and vendors to the power industry\, focusing on s
 upply chain cybersecurity and NERC CIP-013 compliance.\n- Steve Pruskowski
  - Security Test &amp; Evaluation Federal Lead\, Cybersecurity and Infrastruct
 ure Security Agency.\n\nThe panel will be moderated by Johnny Johnson\, Ch
 air of the Richmond IEEE Computer Society\, CISSP (Certified Information S
 ystems Security Professional) with 24 years of experience working in vario
 us government agencies including DHS/CISA\, the Department of Defense and 
 the Department of State.\n\nAnyone interested in joining the open\, cross-
 sector international SBOM effort can email sbom@cisa.dhs.gov\n\nUS Governm
 ent Websites\n\n- Cybersecurity &amp; Infrastructure Security Agency (CISA) SB
 OM main page – https://www.cisa.gov/sbom.\n- National Telecommunications
  and Information Administration (NTIA) SBOM main page – https://www.ntia
 .doc.gov/SBOM.\n\nSBOM Formats\n\n- SPDX SBOM format: https://spdx.dev/\n-
  CycloneDX SBOM and VEX formats: https://cyclonedx.org/\n\nLinux Foundatio
 n\n\n- The State of Software Bill of Materials (SBOM) and Cybersecurity Re
 adiness - https://www.linuxfoundation.org/tools/the-state-of-software-bill
 -of-materials-sbom-and-cybersecurity-readiness/\n- Free SBOM Course – ht
 tps://training.linuxfoundation.org/training/generating-a-software-bill-of-
 materials-sbom-lfc192/.\n\nVirtual: https://events.vtools.ieee.org/m/31170
 2
LOCATION:Virtual: https://events.vtools.ieee.org/m/311702
ORGANIZER:allen.jones@ieee.org
SEQUENCE:12
SUMMARY:Cyber Security Panel Session - Software Bill of Materials
URL;VALUE=URI:https://events.vtools.ieee.org/m/311702
X-ALT-DESC:Description: &lt;br /&gt;&lt;p&gt;&lt;strong&gt;This meeting was recorded. You can
  view the meeting at &lt;a href=&quot;https://youtu.be/W1CEtzhTJQ4&quot;&gt;https://youtu.
 be/W1CEtzhTJQ4&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;\n&lt;p&gt;Did you have to deal with the Log4j o
 r Spring4Shell vulnerability? How much time have you spent just tracking d
 own whether your company&#39;s software was affected by these problems? Do you
  even know what all of the components are that are included\, either direc
 tly or indirectly\, in your software? How prepared are you for dealing wit
 h the next Zero Day vulnerability?&lt;/p&gt;\n&lt;p&gt;Join us for this panel session 
 to discuss the role of a &lt;a href=&quot;https://www.cisa.gov/sbom&quot;&gt;Software Bill
  of Materials&lt;/a&gt; as part of your software development process.&lt;/p&gt;\n&lt;p&gt;Pa
 nelists include:&lt;/p&gt;\n&lt;ul&gt;\n&lt;li&gt;Allan Friedman - Leading CISA&#39;s efforts to
  coordinate SBOM efforts inside and outside the US Government and around t
 he world.&lt;/li&gt;\n&lt;li&gt;L Jean Camp\, IEEE Fellow\, Professor of Informatics &amp;
 amp\; Computer Science. Center Director\, Security &amp;amp\; Privacy in Infor
 matics\, Computing\, &amp;amp\; Engineering at Indiana University (SPICE)&lt;/li&gt;
 \n&lt;li&gt;Tom Alrich - Co-lead for the National Telecommunications and Informa
 tion Adminstration&#39;s Energy SBOM Proof of Concept. Consultant to electric 
 power industry clients and vendors to the power industry\, focusing on sup
 ply chain cybersecurity and NERC CIP-013 compliance.&lt;/li&gt;\n&lt;li&gt;Steve Prusk
 owski - Security Test &amp;amp\; Evaluation Federal Lead\, Cybersecurity and I
 nfrastructure Security Agency.&lt;/li&gt;\n&lt;/ul&gt;\n&lt;p&gt;The panel will be moderated
  by Johnny Johnson\, Chair of the Richmond IEEE Computer Society\, CISSP (
 Certified Information Systems Security Professional) with 24 years of expe
 rience working in various government agencies including DHS/CISA\, the Dep
 artment of Defense and the Department of State.&lt;/p&gt;\n&lt;p&gt;Anyone interested 
 in joining the open\, cross-sector international SBOM effort can email sbo
 m@cisa.dhs.gov&lt;/p&gt;\n&lt;p&gt;&lt;strong&gt;US Government Websites&lt;/strong&gt;&lt;/p&gt;\n&lt;ul&gt;\n
 &lt;li&gt;Cybersecurity &amp;amp\; Infrastructure Security Agency (CISA) SBOM main p
 age &amp;ndash\; &lt;a href=&quot;https://www.cisa.gov/sbom&quot;&gt;https://www.cisa.gov/sbom
 &lt;/a&gt;.&lt;/li&gt;\n&lt;li&gt;National Telecommunications and Information Administration
  (NTIA) SBOM main page &amp;ndash\; &lt;a href=&quot;https://www.ntia.doc.gov/SBOM&quot;&gt;ht
 tps://www.ntia.doc.gov/SBOM&lt;/a&gt;.&lt;/li&gt;\n&lt;/ul&gt;\n&lt;p&gt;&lt;strong&gt;SBOM Formats&lt;/str
 ong&gt;&lt;/p&gt;\n&lt;ul&gt;\n&lt;li&gt;SPDX SBOM format: &lt;a href=&quot;https://spdx.dev/&quot;&gt;https://
 spdx.dev/&lt;/a&gt;&lt;/li&gt;\n&lt;li&gt;CycloneDX SBOM and VEX formats: &lt;a href=&quot;https://c
 yclonedx.org/&quot;&gt;https://cyclonedx.org/&lt;/a&gt;&lt;/li&gt;\n&lt;/ul&gt;\n&lt;p&gt;&lt;strong&gt;Linux Fo
 undation&lt;/strong&gt;&lt;/p&gt;\n&lt;ul&gt;\n&lt;li&gt;The State of Software Bill of Materials (
 SBOM) and Cybersecurity Readiness - &lt;a href=&quot;https://www.linuxfoundation.o
 rg/tools/the-state-of-software-bill-of-materials-sbom-and-cybersecurity-re
 adiness/&quot;&gt;https://www.linuxfoundation.org/tools/the-state-of-software-bill
 -of-materials-sbom-and-cybersecurity-readiness/&lt;/a&gt;&lt;/li&gt;\n&lt;li&gt;Free SBOM Co
 urse &amp;ndash\; &lt;a href=&quot;https://training.linuxfoundation.org/training/gener
 ating-a-software-bill-of-materials-sbom-lfc192/&quot;&gt;https://training.linuxfou
 ndation.org/training/generating-a-software-bill-of-materials-sbom-lfc192/&lt;
 /a&gt;.&lt;/li&gt;\n&lt;/ul&gt;
END:VEVENT
END:VCALENDAR

