You are leaving our Website
Using an external Link:
You are now leaving our website. The following page is operated by a third party. We accept no responsibility for the content, data protection, or security of the linked page..
URL:
BS130: CSAF 2.1 General Training – Security Advisories from the basics through the creation to the distribution NEW
Training: Security - Governance, Risk & Compliance
The five-day, hands-on workshop CSAF 2.1 General Training – Security Advisories from the basics through the creation to the distribution teaches manufacturers and operators how to use CSAF 2.1 for machine-readable Security Advisories and scalable vulnerability management. You create valid Advisories using Secvisogram, Sec-O-Simple, and CSAF Validator, work with all eight CSAF profiles, and structure complex content according to best practices. You then set up a CSAF Provider and work through the process through to automated retrieval by an Aggregator.
Unfortunately there are currently no available appointments.
Would you like to request an appointment? Then click on 'No matching appointment?'
Agenda:
CSAF fundamentals and authoring security advisories
Introduction to CSAF: motivation, benefits and its place in vulnerability management
The CSAF ecosystem at a glance: consumers and producers
Structure of a CSAF document: document, product tree, vulnerabilities
What is new in CSAF 2.1 compared to 2.0
Tools for authoring and validation: Secvisogram, Sec-O-Simple (simplified CSAF editor with product database), CSAF Validator
Hands-on exercises: creating, validating and iteratively improving your first advisories
Practical explanations of common pitfalls and sources of error
Deep dive: profiles, complex advisories and quality
All eight CSAF profiles and their use cases: CSAF Base, Security Incident Response, Informational Advisory, Security Advisory, VEX, Deprecated Security Advisory, plus the profiles newly introduced in CSAF 2.1: Withdrawn and Superseded
Special cases in the advisory lifecycle: withdrawing (Withdrawn) and replacing (Superseded) already published documents
VEX (Vulnerability Exploitability eXchange) in the CSAF context
Complex advisories with multiple vulnerabilities, products, versions and relationships
The product tree in detail: branches, product identification helpers, relationships
Best practices and guidelines for high-quality, machine-processable CSAF documents
Working with CLI tools and JSON files
Extensive hands-on exercises on the profiles
Distribution and the user perspective
The roles of publisher, trusted provider and aggregator in practice: requirements and obligations
Building a CSAF repository: directory structure, provider-metadata.json, index files and ROLIE feeds, hashes and signatures
Setting up your own CSAF provider and publishing advisories
Automated retrieval and consolidation from multiple sources (aggregator, downloader)
Open-source tools for distribution and operations
The user perspective: how recipients process CSAF documents, determine whether they are affected and integrate advisories into their own processes
End-to-end exercise: from authoring an advisory through publication to automated retrieval
Objectives:
In this workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution you will learn how to:
Understand what CSAF is and the value the standard brings to your organisation and your customers
Independently create and structure valid CSAF security advisories based on CSAF 2.1
Use tools such as Secvisogram, Sec-O-Simple and the CSAF Validator for authoring and validation
Know all eight CSAF profiles – including the Withdrawn and Superseded profiles new in CSAF 2.1 – and apply the right one for each use case
Build complex advisories covering multiple vulnerabilities and products in a structured way
Apply best practices and guidelines for high-quality CSAF documents
Understand the roles of CSAF publisher, trusted provider and aggregator and implement them in practice
Deploy your own CSAF provider and publish advisories including the required metadata
Automatically retrieve and consolidate security advisories from multiple sources
Understand how users process CSAF documents and design your advisories accordingly
Target audience:
The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution is aimed at professionals who create, publish or process security advisories and want to master CSAF end to end – from the first document to production distribution:
Members of product security teams and PSIRTs
Product security officers in organisations
Staff of CERTs and IT security departments
IT security engineers and system administrators who provide CSAF advisories internally or publicly
Developers and DevOps engineers automating the distribution of security information
IT professionals in vulnerability management and security researchers
Product security managers integrating CSAF into existing vulnerability management processes
Manufacturers and operators who need to meet the requirements of NIS 2 and the Cyber Resilience Act (CRA) regarding vulnerability handling and security advisories
No prior knowledge of CSAF is required – the workshop starts with the fundamentals. Participants with CSAF experience will benefit from the in-depth coverage of the profiles and the distribution part.
Prerequisites:
To take part in the Workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution, you should meet the following prerequisites:
A basic understanding of IT security and software vulnerabilities is helpful but not mandatory
Experience with JSON files and command-line tools is an advantage (some exercises use CLI tools)
For the distribution part: basic programming skills in Python and a basic understanding of operating web services
Fluent English, both written and spoken, is essential as the workshop is held in English
Willingness to engage intensively and hands-on with a new standard
Description:
Manually gathering vulnerability information from vendor portals, PDFs and mailing lists costs time – and time is exactly what is missing when an incident occurs. The Common Security Advisory Framework (CSAF) solves this problem: the open OASIS standard makes security advisories machine-readable, so recipients can automatically determine whether and which of their products are affected. For manufacturers, NIS 2 and the Cyber Resilience Act are increasingly turning CSAF into an obligation; for operators, it is the tool for scalable vulnerability management.
The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution covers the standard completely and end to end in five days. You start with the structure of a valid CSAF document and create your first advisories using Secvisogram, Sec-O-Simple and the CSAF Validator. You then deepen your knowledge of all eight CSAF profiles – including the Withdrawn and Superseded profiles newly introduced in CSAF 2.1 – and structure complex advisories with multiple vulnerabilities, products and relationships according to best practices. In the final part you set up your own CSAF provider, retrieve advisories automatically from multiple sources and switch to the user perspective: how are your advisories processed on the receiving end, and how do you design them to deliver the greatest possible benefit?
The workshop is hands-on throughout. In a concluding end-to-end exercise you run through the entire process, from authoring an advisory and publishing it on your own provider to automated retrieval by an aggregator. The workshop is based on CSAF 2.1; should the final OASIS Standard not yet be available at the time of the training, we will work with the most recently published Committee Specification Draft or the current state of the TC repository.
The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution is based on CSAF 2.1. Should the final OASIS Standard not yet be available at the time of the training, we will work with the most recently published version (Committee Specification Draft) or the current state of the OASIS CSAF Technical Committee repository.
Other Info:
The course language and course materials are in English.
Individual parts of the workshop cannot be booked separately.
Guaranteed implementation:
from 2 Attendees
Booking information:
Duration:
5 Days
Price:
1.490,00 € plus VAT.
For in-person attendance, lunch and beverages are included in the price.
No appointment available
Authorized training partner
Memberships
Shopping cart
BS130: CSAF 2.1 General Training – Security Advisories from the basics through the creation to the distribution
was added to the shopping cart.