Supply Chain security is a new buzzword for past 2-3 years, the dust is slowly settling and we are now in the phase we people need to evaluate what is going right and what is going wrong.
Large number of organizations, introduced SCA tooling and SBoM creation tooling and called it the day. Has that helped? What has been going on in the world of supply chain security.
In this talk we will explore the Supply chain security not just from a code base dependency prospective but rather wholistic approach to establishing the right controls in the system for a seamless software delivery.
Software supply chain security concerns not just the product organizations creating software of external or internal usage but also for organizations that may be just using the final product as an end user.
From your development environment to production, from downloading binaries from internet to running them on network machines we will explore the 360 degree view of supply chain security, the relevant case studies around the exploitation and what is it that industry or Govt bodies have done towards protecting people or organizations against such attacks.
Audience will leave with a holistic view of how the full supply chain of the software development looks like and thoughts on what are the possible gaps in security they might have in their organizations.
The Digital Personal Data Protection (DPDP) Act is set to redefine how the banking sector handles personal data, ushering in a new era of security and consumer trust. This panel will dive into how the Act is revolutionizing data protection practices, highlighting the challenges and innovations banks face as they adapt to this sweeping regulation. With the rapid rise of digital banking and data-driven technologies, ensuring consumer privacy is more critical than ever. Experts will explore the transformative impact of the DPDP Act on data management, compliance strategies, and the evolving risks of cyber threats. This conversation will also examine how banks can stay ahead of regulatory demands while continuing to innovate. Discover how the DPDP Act is not just a regulatory challenge, but a unique opportunity to build a more secure and transparent financial ecosystem.
Anant Shrivastava is an information security professional with 15+ yrs of corporate experience in Network, Mobile, Application and Linux Security. Anant is an avid opensource supporter and runs multiple opensource projects prominent of them being TamerPlatform and CodeVigilant.
He contributes to multiple Open communities like null and Garage4Hackers. He has also helped establishing local chapter in his hometown null Bhopal
He has been a speaker and a trainer at a multitude of conferences such as Black Hat, Defcon, Nullcon, c0c0n, Rootconf, various bsides events and many more).
He also participates in various communities as a cfp reviewer. Notable of them being Blackhat , nullcon, recon village @ Defcon, cloud village @ defcon, Adversary Village @ defcon. He also supports multiple regional conferences like Bsides Bangalore, Bsides Goa
His public activities are listed in his timeline. His code contributions can be found on Github. He is active on Fediverse and Twitter and his talks and presentations can be found here.
He writes about his experiments at his blog. He can be contacted over email - anant at anantshri dot info