Loading…
Attending this event?
September 30 - October 1, 2024 | New York, New York
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source in Finance Forum New York 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Savings Time (EDT). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Security clear filter
arrow_back View All Dates
Monday, September 30
 

2:30pm EDT

Two Layers of Protection: How FINOS is Securing Projects and Member Supply Chains - Brian Fox, Sonatype
Monday September 30, 2024 2:30pm - 3:00pm EDT
Improving software supply chain security starts with a secure foundation. The FINOS community has recently intensified efforts to help members enhance software supply chain security on two critical fronts:

1. Empowering maintainers to assess and improve their dependency ingestion with access to enterprise-grade software composition analysis (SCA)
2. Providing in-depth dependency consumption analysis, including a detailed review of member downloads from Maven Central

In this presentation, Brian Fox, co-founder of Sonatype, the maintainers of Maven Central, will explore the tangible risks the FINOS community is addressing through these initiatives. He’ll walk through a detailed consumption analysis report from Maven Central, sharing industry insights, what these trends reveal about software supply chain risks, and actionable steps organizations can take to enhance their security posture. Additionally, he’ll provide an overview of the SCA tools available to maintainers to reduce risk and improve delivery across FINOS projects.
Speakers
avatar for Brian Fox

Brian Fox

Cofounder & CTO, Sonatype
Co-founder and CTO, Brian Fox is a Governing Board member for the Opensource Security Foundation, a member of the Apache Software Foundation and former Chair of the Apache Maven project. As a direct contributor to the Maven ecosystem, including the maven-dependency-plugin and maven-enforcer-plugin... Read More →
Monday September 30, 2024 2:30pm - 3:00pm EDT
Royale + Plymouth

2:30pm EDT

Unlocking Secure, Open Supply Chains - Emily Fox, Red Hat
Monday September 30, 2024 2:30pm - 3:00pm EDT
Consuming open source is only a risky proposition if you don’t take the time to engineer a process that mitigates risk through security best practices of open source. Building a program for your organization to securely consume and contribute to open source is no different than developing new software. It is entirely determined by the practices, policies, technical controls, risk tolerance, and culture you establish and reinforce. From your software supply chain to your running services, open source can be both a reference and a guide to conducting the necessary diligence so that your investment in open source is a reward for you, your engineers, and your business. In this talk, we’ll explore assumptions about open source and open source security, tactics for managing secure open source consumption, reducing or mitigating risk presented by open source, and how to successfully use triangle composition to drive your efforts.
Speakers
avatar for Emily Fox

Emily Fox

Emerging Technologies Security Lead, Red Hat
Emily Fox is a DevOps enthusiast, security unicorn, and advocate for Women in Technology. She promotes the cross-pollination of development and security practices. She has worked in security for over 14 years to drive a cultural change where security is unobstructive, natural, and... Read More →
Monday September 30, 2024 2:30pm - 3:00pm EDT
Music Box

3:10pm EDT

Mastering the Cloud Native Wave: Security Resilience in Modern Systems - Andrew Martin & Francesco Beltramini, ControlPlane
Monday September 30, 2024 3:10pm - 3:40pm EDT
Cloud native technologies bring a significant change to the technological landscape, offering unprecedented levels of agility and scalability to modernise IT infrastructure and systems. However, they may potentially introduce substantial added complexity, widen the skills gap, and enlarge the attack surface. Unmanaged adoption will inevitably result in increased risk for any organisation. Security domains and disciplines like open source ingestion, AI/ML secops, threat modeling, security architecture, engineering and incident response need to adapt to the cloud native ecosystem to remain effective. We'll present the most common pain points and pitfalls, to then provide an overview of available countermeasures based on 200+ combined years of cloud native expertise.

Key takeaways: Attendees will be presented with practical techniques to improve common security disciplines (threat modeling, security architecture, engineering, and incident response) for modern cloud-native systems. They will leave with an understanding of what enhancements are required to maximise their usability and effectiveness.

Attendees will be presented with (i) an overview of challenges associated with cloud native technologies, (ii) a focus on risks and skill gaps, (iii) practical techniques to improve common security disciplines (threat modelling, security architecture, engineering, and incident response) for modern cloud native systems, (iv) an understanding of what enhancements are required to maximise their usability and effectiveness, (iv) a reusable methodology for de-risking cloud native technologies adoption.
Speakers
avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →
avatar for Francesco Beltramini

Francesco Beltramini

Head of Technical Solutions, ControlPlane
Francesco is a Security Professional with 10+ years of working experience and deep technical competence matured on a number of high-end projects for both public and private sector organisations. Francesco had the opportunity of working on a variety of technology stacks in designing... Read More →
Monday September 30, 2024 3:10pm - 3:40pm EDT
Music Box

4:10pm EDT

A Journey from Security Architecture to Straight-Through Provisioning - Aldwin Saugere & Iva Nikolaeva, Morgan Stanley
Monday September 30, 2024 4:10pm - 4:40pm EDT
This interactive session will delve into how Security Architecture reviews can be drastically accelerated using architecture patterns and the Common Architecture Language Model (CALM). The security domain of CALM will be presented through a case study using the TraderX FINOS project (sample Trading Application built for educational and experimentation purposes). Presentation highlights: Security Architecture – delineating between design reviews and security assurance to introduce Permit to Build vs. Operate. Architecture patterns – removing friction from security assurance with straight-through permits. Architecture as Code – overview of CALM, its core schema and various domains. Security Domain – utilizing TraderX in the FINOS Tech Sprint 2024 Hackathon to build the Security Domain of CALM. Straight-through provisioning – automating security assurance using architecture patterns and CALM. Adoption – leveraging CALM in the architecture and developer community. Contribution – Architecture as Code Working Group (FINOS DevOps SIG) and On-site Accelerators at Morgan Stanley and London Stock Exchange Group.
Speakers
avatar for Iva Nikolaeva

Iva Nikolaeva

Cybersecurity Architect, Morgan Stanley
Iva is a Security Architect in Morgan Stanley where she provides support and security guidance to a wide variety of technology teams and Strategists. She enables and guides teams on their journey through designing and building applications and through cloud adoption by advising on... Read More →
avatar for Aldwin Saugere

Aldwin Saugere

EMEA Head of Security Architecture, Morgan Stanley
Aldwin is the EMEA Head of Security Architecture at Morgan Stanley. The team provides Security Design consulting services and delivers Security Assurance for systems built by Morgan Stanley hosted on-premises and/or by Cloud Service Providers. Aldwin's team also preforms Security... Read More →
Monday September 30, 2024 4:10pm - 4:40pm EDT
Music Box
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -