BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Strengthening the CVE Ecosystem (Seating is limited 
 to 50\n   Participants)\n   Tags: Policy @ DEF CON | Creator Interactive T
 alk/Panel\n   When: Friday\, Aug 7\, 14:00 - 15:30 PDT\n   Where: LVCCW Le
 vel 2 W210-211 (Policy Village) - [1]Map\n\n   Description:\n\n   CVE is c
 ore infrastructure for vulnerability management\, but itâ€™s\n   under rea
 l strain. The volume and complexity of vulnerabilities keep\n   rising\, w
 hile the systems\, tooling\, and coordination models behind CVE\n   havenâ
 €™t kept pace. This was true prior to the extensive use of AI to\n   ident
 ify vulnerabilities and has only grown more acute. At the same\n   time\, 
 governments and industry are relying on CVE data more than ever\n   to dri
 ve security decisions\, and there are concerns about whether\n   current f
 unding models are sustainable. This roundtable brings\n   together the peo
 ple who actually work with CVE (researchers\,\n   open-source maintainers\
 , vendors\, and policymakers) to talk frankly\n   about whatâ€™s breaking 
 and what needs to change. Weâ€™ll focus on\n   three areas: gaps in CVE da
 ta and infrastructure\, where automation and\n   AI can realistically help
 \, and how to build sustainable public-private\n   support for the ecosyst
 em - all with the goal of identifying concrete\n   policy steps that could
  improve CVE over the next 12-24 months. This\n   discussion would feed in
 to a policy paper making recommendations for\n   policymakers\, published 
 by the Center for Cybersecurity Policy and\n   Law.\n\n   Seating is limit
 ed to the first 50 participants in order to facilitate\n   interactive dis
 cussion.\n\n   Speakers:John Banghart\,Elizabeth Eigner\,Lisa Olsen\,Linds
 ey Cerkovnik\n\n   SpeakerBio:  John Banghart\, Center for Cybersecurity P
 olicy & Law\n\n   John Banghart leverages his significant federal governme
 nt and private\n   sector experience in cybersecurity to navigate issues r
 elated to risk\n   management\, government policy\, standards and regulato
 ry compliance\,\n   and incident management. He has successfully led effor
 ts to address\n   significant and high-profile cybersecurity issues within
  major\n   government programs and institutions while facing complex legal
 \,\n   technical\, and political circumstances. From 2013 to 2015\, John p
 layed\n   a key role in developing the Obama administration's cybersecurit
 y and\n   technology policy as the National Security Council's director fo
 r\n   federal cybersecurity. He led policy\, technical\, and process effor
 ts\n   to reduce cybersecurity risk and improve metrics and measurement fo
 r\n   all civilian\, military\, and intelligence community agencies. He se
 rved\n   as a primary advisor on cybersecurity incidents and preparedness 
 and\n   led the National Security Councilâ€™s efforts to address significa
 nt\n   cybersecurity incidents\, including those at OPM and the White Hous
 e\,\n   among others. He also spent several years at the National Institut
 e of\n   Standards and Technology (NIST)\, both as a cybersecurity researc
 her\n   and in the Office of the Undersecretary of Commerce for Standards 
 and\n   Technology. John also worked as a senior cybersecurity advisor for
  the\n   Centers for Medicare and Medicaid Services\, providing leadership
  to\n   the cybersecurity preparations for the Healthcare.gov website.\n\n
    SpeakerBio:  Elizabeth Eigner\, Microsoft\n\n   Elizabeth Eigner is a S
 enior Manager on Microsoftâ€™s Global\n   Cybersecurity Policy team\, wher
 e she leads Microsoft's vulnerability\n   policy portfolio\, overseeing ef
 forts to develop and implement\n   strategies that address vulnerability m
 anagement both in the United\n   States and globally. She represents Micro
 soft on the Hacking Policy\n   Council\, where she works collaboratively w
 ith industry leaders and\n   policymakers to advance responsible cybersecu
 rity and strengthen the\n   frameworks that underpin software security wor
 ldwide. Elizabeth also\n   leads initiatives aimed at creating and enhanci
 ng national cyber\n   strategies in countries around the world. She works 
 closely with\n   governments and stakeholders to strengthen policy framewo
 rks and\n   promote resilient cybersecurity practices globally. Elizabeth 
 also\n   leads Microsoft's Advancing Regional Cybersecurity (ARC) initiati
 ve\,\n   focusing on improving incident response capabilities and cyber\n 
   capacity building in the Global South. Previously\, she served as\n   Mi
 crosoftâ€™s representative on the Cloud Service Provider Advisory\n   Boar
 d (CSP-AB)\, contributing to FedRAMP public policy discussions and\n   bes
 t practices for cloud security. Before joining Microsoft\, Elizabeth\n   w
 orked at The Washington Technology Industry Association to enhance\n   Was
 hington State's innovation ecosystem. At MIT Solve\, she\n   collaborated 
 with tech-based social entrepreneurs on solutions\n   fostering digital in
 clusion and equitable economic opportunity. She\n   holds a B.S. in Politi
 cal Science from Northeastern University\, with\n   concentrations in Law 
 and International Security.\n\n   SpeakerBio:  Lisa Olsen\, Principal Secu
 rity Release Program Manager at\n   Microsoft\n\n   Lisa Olson is a Princi
 pal Security Release Program Manager at\n   Microsoft\, where she has led 
 the Patch Tuesday release process since\n   2013. A member of the CVE Boar
 d since 2018\, Lisa is a passionate\n   advocate for improving vulnerabili
 ty communication through automation\n   and machine-readable formats. Her 
 work focuses on transforming how\n   security information is shared to hel
 p organizations respond faster\n   and more effectively.\n\n   SpeakerBio:
   Lindsey Cerkovnik\, CISA\n\n   Lindsey Cerkovnik is the Chief of CISAâ€™
 s Vulnerability Response &\n   Coordination (VRC) Branch. Her team is resp
 onsible for CISAâ€™s\n   Coordinated Vulnerability Disclosure (CVD) proces
 s\, the Known\n   Exploited Vulnerabilities (KEV) catalog\, and CISAâ€™s S
 takeholder\n   Specific Vulnerability Categorization (SSVC) process. Linds
 ey and her\n   team help to maintain\, support\, and advance the global vu
 lnerability\n   ecosystem by funding and overseeing the CVE and CVE Number
 ing\n   Authority (CNA) programs\, leading the production and disseminatio
 n of\n   machine-readable vulnerability enrichment information\, and engag
 ing in\n   valuable technical collaboration with the vulnerability researc
 h\n   community.\n\n   '\n\n   1. #LVCCW_Level2_West\n\n\n
DTEND:20260807T223000Z
DTSTART:20260807T210000Z
LOCATION:Policy @ DEF  CON - LVCCW Level 2 W210-211 (Policy Village)
SUMMARY:Strengthening the CVE Ecosystem (Seating is limited to 50 Participa
 nts)
END:VEVENT
END:VCALENDAR
