Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

Working Group

Vulnerability Data

The mission of this working group is to identify and understand the problems around vulnerability discovery, reporting, publication, tracking, and classification.
View Current Projects
Global Security Database Working Group Charter
Global Security Database Working Group Charter

Download

Vulnerability Data

What is the GSD?

GSD, or Global Security Database, is meant to be a fast, cooperative, royalty-free, and public collection of security information. The project uses the open source model to overcome many of the existing shortcomings of security databases such as being difficult to access, update, and restricted use of the security information. GSD is sponsored by the Cloud Security Alliance, a nonprofit organization, in order to have a neutral home for the project. We welcome anyone to request new security identifiers, submit updates to existing security identifiers, contribute ideas to the project, and drive the group to fulfill community needs around vulnerability identifiers.

Working Group Overview
Our working group meets twice a month on Tuesdays at 9am PT. We welcome anyone who would like to join, even if you would like to just listen in on your first call.

See the exact dates on the working group calendar at: https://csaurl.org/gsd-calendar

What do we discuss? 
During our meetings we typically discuss updates to the GSD project, and plan future efforts. This working group meets every other week. 

Drafts & Important Docs

Working Group Leadership

Josh Bressers
Josh Bressers

Josh Bressers

Product Security Technical Lead

Josh Bressers is the Vice President of Security at Anchore. Josh has helped build and manage product security teams for open source projects as well as several organizations. Everything from managing supply chains, vulnerabilities, security development lifecycle, DevSecOps, security product management, security strategy, and nearly any other task that falls under the security umbrella. Josh co-hosts the Open Source Security Podc...

Read more

Kurt Seifried
Kurt Seifried

Kurt Seifried

Chief Innovation Officer, CSA

For over two decades, Kurt has excelled in information security, starting with Windows and Linux, and advancing to cloud computing and AI. With a strong focus on AI security, privacy, and open source, Kurt brings extensive expertise to the Cloud Security Alliance (CSA).

Read more

Publications in ReviewOpen Until
Context-Based Access Control for Zero TrustNov 27, 2024
Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity ProfessionalsDec 06, 2024
AI Organizational Responsibilities: AI Tools and ApplicationsDec 08, 2024
Zero Trust Guidance for Small and Medium Size Businesses (SMBs)Dec 15, 2024
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Virtual Meetings

Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.

Dec

3

Tue, December 3, 9:00am - 10:00am PST
Vulnerability Data Working Group
See details
Biweekly CSA Vulnerability Data Working Group Meeting

Useful links:

Links to the draft documents can be found in the #vuln-data-working-group Slack channel bookmarks at the top of the screen.

Dec

17

Tue, December 17, 9:00am - 10:00am PST
Vulnerability Data Working Group
See details
Biweekly CSA Vulnerability Data Working Group Meeting

Useful links:

Links to the draft documents can be found in the #vuln-data-working-group Slack channel bookmarks at the top of the screen.

Dec

31

Tue, December 31, 9:00am - 10:00am PST
Vulnerability Data Working Group
See details
Biweekly CSA Vulnerability Data Working Group Meeting

Useful links:

Links to the draft documents can be found in the #vuln-data-working-group Slack channel bookmarks at the top of the screen.

Jan

14

Tue, January 14, 9:00am - 10:00am PST
Vulnerability Data Working Group
See details
Biweekly CSA Vulnerability Data Working Group Meeting

Useful links:

Links to the draft documents can be found in the #vuln-data-working-group Slack channel bookmarks at the top of the screen.

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Context-Based Access Control for Zero Trust

Open Until: 11/27/2024

The document "Context-Based Access Control for Zero Trust" provides guidance on implementing context-based access control (...

Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity Professionals

Open Until: 12/06/2024

The document Fully Homomorphic Encryption: A Comprehensive Guide for Cybersecurity Professionals serves as an in-d...

AI Organizational Responsibilities: AI Tools and Applications

Open Until: 12/08/2024

The integration of LLMs and Generative AI introduces vital security considerations across development and deployment proces...

Zero Trust Guidance for Small and Medium Size Businesses (SMBs)

Open Until: 12/15/2024

In an increasingly digital world, small and medium-sized businesses (SMBs) are facing heightened security challenges, makin...