From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 24,700 courses taught by industry experts.
Use a CVE and CWE to describe a GitHub Advanced Security alert and list potential remediation - GitHub Tutorial
From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Use a CVE and CWE to describe a GitHub Advanced Security alert and list potential remediation
- [Instructor] Yes. The main theme of this certification exam objective in this particular lesson is a call out to the deep integration between the GitHub Advanced Security Alert System and the Vendor Neutral CVE and CWE Systems. This is the language of vulnerabilities, CVE, Common Vulnerabilities and Exposures, uniquely identify security flaws. These are formalized articles that serve as a public disclosure of a known vulnerability, it's remediation, et cetera. CwEs are more broad in their scope. They categorize vulnerabilities that could be future problems and expose additional vulnerabilities in the future. You see, and the idea here is, and we've seen this, GitHub Advanced Security links any of your alerts that align to known published CVEs and CWEs, which is going to be useful to everybody. Because it allows you to make a faster diagnosis and do your remediation. Now, another element of standardization is that CVEs typically carry yet another acronym, CVSS, Common Vulnerability…
Contents
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
(Locked)
Learning objectives40s
-
(Locked)
Use a CVE and CWE to describe a GitHub Advanced Security alert and list potential remediation3m 34s
-
(Locked)
Advanced security alert and list potential remediation1m 48s
-
(Locked)
Describe the decision-making process for closing and dismissing security alerts1m 21s
-
(Locked)
Determine the roles and responsibilities of development and security teams on a software development workflow1m 4s
-
(Locked)
Explain how to set a review cadence with security teams when appropriate1m 37s
-
(Locked)
Use security policies to instruct all contributors to better secure their repositories2m 4s
-
(Locked)
Compare the code scanning alert against the repository's security policy53s
-
(Locked)
Align repository branch protection configuration with written security policies11m 24s
-
(Locked)
-
-