qSkills™ AI Agent
qS
Hello! Ask me about training courses, certifications, schedules or anything else on qskills.de—just in your own words.
0/800

BS130: CSAF 2.1 General Training – Security Advisories from the basics through the creation to the distribution NEW

Training: Security - Governance, Risk & Compliance

Allianz für Cyber Sicherheit Partner Logo Vektor

The five-day, hands-on workshop CSAF 2.1 General Training – Security Advisories from the basics through the creation to the distribution teaches manufacturers and operators how to use CSAF 2.1 for machine-readable Security Advisories and scalable vulnerability management. You create valid Advisories using Secvisogram, Sec-O-Simple, and CSAF Validator, work with all eight CSAF profiles, and structure complex content according to best practices. You then set up a CSAF Provider and work through the process through to automated retrieval by an Aggregator.

Unfortunately there are currently no available appointments.
Would you like to request an appointment? Then click on 'No matching appointment?'

Request prefered appointment period:

* All fields marked with an asterisk are mandatory fields.

Agenda:

  • CSAF fundamentals and authoring security advisories

    • Introduction to CSAF: motivation, benefits and its place in vulnerability management

    • The CSAF ecosystem at a glance: consumers and producers

    • Structure of a CSAF document: document, product tree, vulnerabilities

    • What is new in CSAF 2.1 compared to 2.0

    • Tools for authoring and validation: Secvisogram, Sec-O-Simple (simplified CSAF editor with product database), CSAF Validator

    • Hands-on exercises: creating, validating and iteratively improving your first advisories

    • Practical explanations of common pitfalls and sources of error

  • Deep dive: profiles, complex advisories and quality

    • All eight CSAF profiles and their use cases: CSAF Base, Security Incident Response, Informational Advisory, Security Advisory, VEX, Deprecated Security Advisory, plus the profiles newly introduced in CSAF 2.1: Withdrawn and Superseded

    • Special cases in the advisory lifecycle: withdrawing (Withdrawn) and replacing (Superseded) already published documents

    • VEX (Vulnerability Exploitability eXchange) in the CSAF context

    • Complex advisories with multiple vulnerabilities, products, versions and relationships

    • The product tree in detail: branches, product identification helpers, relationships

    • Best practices and guidelines for high-quality, machine-processable CSAF documents

    • Working with CLI tools and JSON files

    • Extensive hands-on exercises on the profiles

  • Distribution and the user perspective

    • The roles of publisher, trusted provider and aggregator in practice: requirements and obligations

    • Building a CSAF repository: directory structure, provider-metadata.json, index files and ROLIE feeds, hashes and signatures

    • Setting up your own CSAF provider and publishing advisories

    • Automated retrieval and consolidation from multiple sources (aggregator, downloader)

    • Open-source tools for distribution and operations

    • The user perspective: how recipients process CSAF documents, determine whether they are affected and integrate advisories into their own processes

    • End-to-end exercise: from authoring an advisory through publication to automated retrieval

Objectives:

In this workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution you will learn how to:

  • Understand what CSAF is and the value the standard brings to your organisation and your customers

  • Independently create and structure valid CSAF security advisories based on CSAF 2.1

  • Use tools such as Secvisogram, Sec-O-Simple and the CSAF Validator for authoring and validation

  • Know all eight CSAF profiles – including the Withdrawn and Superseded profiles new in CSAF 2.1 – and apply the right one for each use case

  • Build complex advisories covering multiple vulnerabilities and products in a structured way

  • Apply best practices and guidelines for high-quality CSAF documents

  • Understand the roles of CSAF publisher, trusted provider and aggregator and implement them in practice

  • Deploy your own CSAF provider and publish advisories including the required metadata

  • Automatically retrieve and consolidate security advisories from multiple sources

  • Understand how users process CSAF documents and design your advisories accordingly

Target audience:

The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution is aimed at professionals who create, publish or process security advisories and want to master CSAF end to end – from the first document to production distribution:

  • Members of product security teams and PSIRTs

  • Product security officers in organisations

  • Staff of CERTs and IT security departments

  • IT security engineers and system administrators who provide CSAF advisories internally or publicly

  • Developers and DevOps engineers automating the distribution of security information

  • IT professionals in vulnerability management and security researchers

  • Product security managers integrating CSAF into existing vulnerability management processes

  • Manufacturers and operators who need to meet the requirements of NIS 2 and the Cyber Resilience Act (CRA) regarding vulnerability handling and security advisories

No prior knowledge of CSAF is required – the workshop starts with the fundamentals. Participants with CSAF experience will benefit from the in-depth coverage of the profiles and the distribution part.

Prerequisites:

To take part in the Workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution, you should meet the following prerequisites:

  • A basic understanding of IT security and software vulnerabilities is helpful but not mandatory

  • Experience with JSON files and command-line tools is an advantage (some exercises use CLI tools)

  • For the distribution part: basic programming skills in Python and a basic understanding of operating web services

  • Fluent English, both written and spoken, is essential as the workshop is held in English

  • Willingness to engage intensively and hands-on with a new standard

Description:

Manually gathering vulnerability information from vendor portals, PDFs and mailing lists costs time – and time is exactly what is missing when an incident occurs. The Common Security Advisory Framework (CSAF) solves this problem: the open OASIS standard makes security advisories machine-readable, so recipients can automatically determine whether and which of their products are affected. For manufacturers, NIS 2 and the Cyber Resilience Act are increasingly turning CSAF into an obligation; for operators, it is the tool for scalable vulnerability management.

The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution covers the standard completely and end to end in five days. You start with the structure of a valid CSAF document and create your first advisories using Secvisogram, Sec-O-Simple and the CSAF Validator. You then deepen your knowledge of all eight CSAF profiles – including the Withdrawn and Superseded profiles newly introduced in CSAF 2.1 – and structure complex advisories with multiple vulnerabilities, products and relationships according to best practices. In the final part you set up your own CSAF provider, retrieve advisories automatically from multiple sources and switch to the user perspective: how are your advisories processed on the receiving end, and how do you design them to deliver the greatest possible benefit?

The workshop is hands-on throughout. In a concluding end-to-end exercise you run through the entire process, from authoring an advisory and publishing it on your own provider to automated retrieval by an aggregator. The workshop is based on CSAF 2.1; should the final OASIS Standard not yet be available at the time of the training, we will work with the most recently published Committee Specification Draft or the current state of the TC repository.

The workshop BS130: CSAF 2.1 General Training – Security Advisories from the Basics through Authoring to Distribution is based on CSAF 2.1. Should the final OASIS Standard not yet be available at the time of the training, we will work with the most recently published version (Committee Specification Draft) or the current state of the OASIS CSAF Technical Committee repository.

Other Info:

  • The course language and course materials are in English.

  • Individual parts of the workshop cannot be booked separately.

Check Icon

Guaranteed implementation:

from 2 Attendees

Booking information:

Duration:

5 Days

Price:

1.490,00 € plus VAT.

For in-person attendance, lunch and beverages are included in the price.

Authorized training partner

NetApp Partner Authorized Learning
Commvault Training Partner
CQI | IRCA Approved Training Partner
Veeam Authorized Education Center
DEKRA Certification GmbH
AWS Partner Select Tier Training
ISACA Accredited Partner
iSAQB
CompTIA Authorized Partner
EC-Council Accredited Training Center

Memberships

Allianz für Cyber-Sicherheit
TeleTrust Pioneers in IT security
Bundesverband der IT-Sachverständigen und Gutachter e.V.
Bundesverband mittelständische Wirtschaft (BVMW)
Allianz für Sicherheit in der Wirtschaft
NIK - Netzwerk der Digitalwirtschaft
BVSW
Bayern Innovativ
KH-iT
CAST
IHK Nürnberg für Mittelfranken
eato e.V.
Sicherheitsnetzwerk München e.V.