Managing Risk Across the Vulnerability Ecosystem

CVE/FIRST VulnCon 2025 · Main Stage

Overview

In an increasingly interconnected software supply chain, managing vulnerabilities effectively has become a paramount challenge for enterprises. This VulnCon talk, "Managing Risk Across the Vulnerability Ecosystem," delivered by Trisha, Julia, and Cassie from Dell, delves into a comprehensive, multi-disciplinary strategy for achieving trustworthy code and robust product security. The presentation outlines an integrated ecosystem designed to connect disparate security disciplines, from dependency management and third-party risk assessment to product security incident response, all with the ultimate goal of providing transparent and secure products to customers.

Watch on YouTube

Visual summary for Managing Risk Across the Vulnerability Ecosystem
Visual summary for Managing Risk Across the Vulnerability Ecosystem

Key moments

  1. 0:00 Overview of the vulnerability ecosystem
  2. 1:00 Differentiating inventory from SBOMs
  3. 2:30 Open-source trustworthiness score and trusted repository
  4. 4:00 Supplier trustworthiness score and standardization
  5. 6:00 Key outputs: SBOMs, metrics, and VEX
  6. 7:00 Origin of the Dependency Management Platform (DMP)
  7. 8:00 Nuances of inventory disclosure in SBOMs

Managing Risk Across the Vulnerability Ecosystem

Speakers: Trisha (Dependency Management), Julia (Third-Party Risk Management), Cassie (Product Security Incident Response Team), Dell

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=bRscNq3ePCw

Overview

In an increasingly interconnected software supply chain, managing vulnerabilities effectively has become a paramount challenge for enterprises. This VulnCon talk, "Managing Risk Across the Vulnerability Ecosystem," delivered by Trisha, Julia, and Cassie from Dell, delves into a comprehensive, multi-disciplinary strategy for achieving trustworthy code and robust product security. The presentation outlines an integrated ecosystem designed to connect disparate security disciplines, from dependency management and third-party risk assessment to product security incident response, all with the ultimate goal of providing transparent and secure products to customers.

The core of their approach centers on building a cohesive security strategy that addresses the full lifecycle of software components, both internal and external. This includes meticulous inventory management, proactive open-source software (OSS) and supplier trustworthiness scoring, and dynamic vulnerability response mechanisms. By standardizing data intake, automating processes, and fostering accountability across the supply chain, Dell aims to move beyond reactive vulnerability patching to a proactive, "shift-left" security posture that informs development decisions from the outset.

The talk is particularly relevant in the current regulatory landscape, where mandates like Executive Order (EO) 14028 and the Cyber Resilience Act (CRA) emphasize the need for greater transparency and accountability in software components. For any organization grappling with the complexities of modern software development, supply chain security, and regulatory compliance, Dell's detailed framework offers valuable insights into constructing a resilient and trustworthy vulnerability management ecosystem.

Background

▶ Watch: Overview of the vulnerability ecosystem (0:00)

The genesis of Dell's comprehensive vulnerability management ecosystem can be traced back to significant industry events and evolving regulatory pressures. The Log4j vulnerability, a watershed moment for software supply chain security, highlighted the urgent need for enterprises to gain granular visibility into their software components and their associated risks. Prior to this, Dell, like many organizations, relied on Software Composition Analysis (SCA) tools primarily for identifying open-source software. However, Log4j underscored the critical gap in understanding the full impact of vulnerabilities across an entire product portfolio, prompting a re-evaluation of their existing capabilities.

This re-evaluation was further accelerated by Executive Order 14028, which mandated enhanced software supply chain security for federal agencies and, by extension, their suppliers. The EO necessitated a thorough understanding of all components within a product, pushing organizations to develop more robust inventory management practices and embrace the concept of Software Bill of Materials (SBOMs). While initial efforts focused on identifying open-source components, the new directive required a holistic view, encompassing both third-party commercial components and internal shared components.

The challenge was not merely generating SBOMs but integrating this data into a dynamic security framework. Traditional SBOMs, by their nature, are static snapshots of components at a specific point in time, often at release. This static nature posed a significant hurdle for effective Product Security Incident Response Team (PERT) operations, which require up-to-date vulnerability information and the ability to track remediation efforts dynamically. Furthermore, the burgeoning use of open-source software and reliance on numerous third-party suppliers introduced complexities related to component trustworthiness, inconsistent data formats, and fragmented accountability. Dell recognized that a truly effective strategy would require a unified approach, connecting inventory, supplier risk, and vulnerability response into a single, coherent ecosystem, rather than relying on isolated tools and processes.

Key Findings

▶ Watch: Open-source trustworthiness score and trusted repository (2:30)

Dell's presentation outlines several key findings and contributions that form the bedrock of their integrated vulnerability management ecosystem:

  1. Cohesive Ecosystem Strategy: The primary finding is the necessity and successful implementation of a unified ecosystem that connects various security disciplines, including dependency management, third-party risk management (TPRM), and product security incident response (PERT). This moves away from siloed operations towards a holistic security strategy for delivering trustworthy code.
  2. Dependency Management Platform (DMP) as the Central Hub: The establishment of the DMP as the single source of truth for all software components (third-party, open-source, and internal) is a crucial contribution. This platform ingests inventory data, which is distinct from the customer-facing SBOM, allowing for internal transparency and quality checks before external disclosure.
  3. Proactive Trustworthiness Scoring: Dell has developed and integrated Open-Source Software (OSS) trustworthiness scores and Supplier trustworthiness scores. These scores, based on predefined criteria, aim to "shift left" by guiding product teams in making better, more secure choices upfront, reducing the influx of vulnerable components.
  4. Standardized Inventory and Data Quality: A significant effort has been made to standardize naming conventions for suppliers and components, ensuring high-quality inventory data. This includes building wrappers around existing SCA tools to enforce quality standards and kick back non-compliant inventory to business units (BUs) for correction.
  5. Automated Vulnerability Response and VEX Integration: The ecosystem automates the opening of vulnerability response reports for newly identified vulnerabilities, linking them directly to affected products and their specific components. This is coupled with the dynamic application of Vulnerability Exploitability eXchange (VEX) statements, which provide critical context on whether a vulnerability is actually exploitable in a specific product, moving beyond the static nature of SBOMs.
  6. Structured Third-Party Risk Management (TPRM): Dell has implemented a robust TPRM program, including a comprehensive onboarding process for suppliers (inherent risk assessments, security enhanced due diligence, corrective action plans) and a structured escalation process for supplier non-compliance post-contract. This ensures suppliers adhere to Dell's stringent security standards.
  7. Data-Driven Metrics and Accountability: The system generates metrics and dashboards to monitor various aspects, including OSS trustworthiness, supplier remediation effectiveness (e.g., responsiveness, overall effectiveness percentage), and compliance. This data is leveraged by PERT for faster, more effective vulnerability response and to ensure supplier accountability.
  8. Enhanced Customer Transparency and Trust: By providing customer-facing SBOMs, machine-readable advisories, and VEX statements, Dell aims to increase transparency, allowing customers to quickly assess their own risk posture without needing to engage directly with Dell for every vulnerability inquiry. This proactive disclosure builds trust and empowers customers.

Technical Deep Dive

▶ Watch: Supplier trustworthiness score and standardization (4:00)

Dell's vulnerability management ecosystem is architected around several interconnected technical components and processes, designed to provide a comprehensive view of software risk.

At the heart of the system is the Dependency Management Platform (DMP). This platform serves as the central repository for all component inventory, encompassing third-party, open-source, and internal shared components. The intake process for inventory is rigorous: product teams generate an inventory of their components as part of their build pipeline. Dell uses SPDX 2.3 for both intake and export of this information. However, a critical distinction is made between the "inventory" (the internal, comprehensive list of all components) and the "SBOM" (the customer-facing document, which may exclude certain internal or NDA-bound components for disclosure reasons). Before an inventory is accepted into the DMP, it undergoes stringent quality checks. Dell has built custom wrappers around its underlying SCA tool to enforce these standards, ensuring adherence to format and required fields. If an inventory fails these checks, it is kicked back to the business unit (BU) for remediation, guaranteeing a high level of data integrity.

A key "shift-left" initiative is the Open-Source Software (OSS) trustworthiness score. This score is generated based on criteria developed by an internal assurance program and is intended to guide developers. Developers are directed to use a trusted repository for OSS components, preventing arbitrary inclusion of unvetted software. The trustworthiness score, while currently serving as guidance, may evolve into a mandatory gate. The goal is to inform developers upfront about the security posture and maintenance quality of OSS components, thereby reducing vulnerabilities introduced early in the development cycle.

The Third-Party Risk Management (TPRM) program, led by Julia, is deeply integrated into the ecosystem. The process for onboarding a new supplier begins with the product team identifying a need for a component. The supplier then completes an inherent risk assessment, covering security, privacy, and geopolitical risks. For product security, this triggers a security enhanced due diligence questionnaire, aligned with the NIST Cybersecurity Framework and Dell's internal SDL control catalog. Risk subject matter experts review responses, assign a risk rating, and develop corrective action plans for identified gaps, which can be incorporated into contracts. Continuous monitoring, driven by the supplier's risk score, is then established.

Post-contract, the TPRM program includes a structured escalation process for supplier non-compliance regarding security fixes.

  1. Level 1 Escalation: The product team directly contacts the supplier.
  2. Level 2 Escalation (PERT Top Escalation): If Level 1 fails, the Product Security Incident Response Team (PERT) engages the supplier's security team.
  3. Level 3 Escalation (TPRPM Program): If Level 2 fails, the product team, PERT, and TPRM collaborate to create a vulnerability data report for a VP-to-VP conversation with the supplier. This report includes contract terms, risk profile, specific vulnerability issues, and historical evidence. Outcomes can range from adherence to terms to partnership termination.

Metrics are crucial for accountability. Supplier Product Remediation Effectiveness Key Performance Indicators (KPIs) track:

  • Responsiveness: Time taken for suppliers to provide a security fix from initial contact.
  • Overall Effectiveness Percentage: Evaluates a supplier's overall success in addressing vulnerabilities, feeding into the supplier trustworthiness score.
  • Contractual and Risk Assessment Data: Considers signed contracts and pre-contract risk ratings.

Finally, the Product Security Incident Response Team (PERT), as described by Cassie, acts as the ultimate consumer of this integrated data. PERT leverages the dependency inventory, SCA results, supplier security requirement agreements, supplier SBOMs, and VEX statements. The OSS trustworthiness score helps PERT quickly identify vulnerabilities in open-source dependencies and automatically open tickets for affected product teams. Supplier SBOMs facilitate mapping supplier dependencies to internal products, allowing PERT to understand which teams are impacted when a supplier discloses a vulnerability. Supplier risk ratings inform PERT on which suppliers require closer monitoring. Supplier Security Agreements (SSAs), including Service Level Agreements (SLAs) for fixes, provide PERT with the contractual basis to drive remediations and ensure supplier accountability. The goal is to automate the generation of security advisories and VEX statements via an API, enabling customers to programmatically pull information and assess their own risk without direct engagement.

A key philosophical point highlighted is the distinction between an SBOM and VEX: an SBOM is a static document representing components at a release point, while VEX is dynamic, providing real-time exploitability context. Dell maintains these as separate, but intrinsically linked, components of their vulnerability management strategy.

Demo / Proof of Concept

▶ Watch: Origin of the Dependency Management Platform (DMP) (7:00)

The talk focused on presenting Dell's comprehensive framework, processes, and the architecture of their integrated vulnerability management ecosystem. While the speakers extensively described how various components like the Dependency Management Platform (DMP), Third-Party Risk Management (TPRM) processes, and Product Security Incident Response Team (PERT) operations function and interact, there was no specific mention or demonstration of a live demo, a technical proof of concept, or any specific tool outputs during the presentation. The discussion was centered on the strategic implementation and operational workflows rather than a hands-on showcase of the system in action.

Defensive Implications

▶ Watch: Nuances of inventory disclosure in SBOMs (8:00)

The comprehensive vulnerability ecosystem presented by Dell offers several critical defensive implications for organizations aiming to strengthen their software supply chain security:

  1. Implement a Centralized Dependency Management Platform (DMP): Defenders should establish a single source of truth for all software components, both internal and external. This platform should enforce quality standards for inventory data, potentially by building validation wrappers around existing SCA tools, to ensure data accuracy and completeness. Adopting a standardized format like SPDX 2.3 for inventory intake and SBOM export is crucial.
  2. "Shift Left" with Trustworthiness Scoring: Integrate OSS and supplier trustworthiness scores into the development pipeline. This involves creating a trusted repository for open-source components and establishing criteria to assess their security posture and maintenance quality. The goal is to guide developers in making secure choices early, reducing the introduction of vulnerable components into products.
  3. Standardize Data and Naming Conventions: Enforce standardized naming for suppliers and components across the organization. This consistency is vital for accurate cross-inventory analysis, risk assessment, and efficient vulnerability mapping.
  4. Develop a Robust Third-Party Risk Management (TPRM) Program: Implement a structured TPRM program that includes:
  • Inherent risk assessments for new suppliers.
  • Security enhanced due diligence questionnaires aligned with industry frameworks (e.g., NIST CSF) and internal security policies.
  • Corrective action plans for identified gaps.
  • Continuous monitoring of supplier security posture based on risk scores.
  • Clear escalation paths for non-compliance, involving product teams, security incident response, and executive leadership.
  1. Automate Vulnerability Response and Leverage VEX: Automate the creation of vulnerability response reports when new vulnerabilities are identified, linking them directly to affected components and products. Crucially, defenders must leverage Vulnerability Exploitability eXchange (VEX) statements to provide dynamic context on whether a known vulnerability actually poses a risk in their specific product configurations. This allows for more targeted and efficient remediation efforts, reducing alert fatigue.
  2. Demand Supplier SBOMs and SLAs: Require suppliers to provide SBOMs for their components and establish clear Service Level Agreements (SLAs) for vulnerability remediation within contracts. This ensures accountability and provides defenders with the necessary information to manage downstream risks effectively. Monitoring supplier remediation effectiveness through KPIs (e.g., responsiveness, effectiveness percentage) is essential.
  3. Prioritize Customer Transparency: Prepare to provide transparent, machine-readable security advisories, SBOMs, and VEX statements to customers. This proactive approach builds trust and empowers customers to assess their own risk more effectively, reducing the burden on internal support teams.
  4. Integrate Metrics for Executive Visibility: Develop dashboards that consolidate security metrics, risks, and compliance status for each product. This "product 360 view" provides executives with comprehensive insights, enabling informed decision-making and resource allocation.

By adopting these defensive strategies, organizations can move towards a more proactive, data-driven, and transparent approach to managing risk across their entire vulnerability ecosystem, ultimately delivering more secure products and enhancing customer trust.

Key Takeaways

  • Holistic Ecosystem Integration is Essential: Effective vulnerability management requires a cohesive strategy that integrates dependency management, third-party risk, and incident response, moving beyond siloed security functions.
  • "Shift Left" for Proactive Security: By introducing OSS and supplier trustworthiness scores and vetting processes early in the development lifecycle, organizations can guide developers to make better choices, preventing vulnerabilities before they are introduced.
  • Data Quality Drives Effectiveness: Standardizing component inventory, enforcing quality checks, and maintaining a robust Dependency Management Platform (DMP) are foundational for accurate vulnerability mapping and response.
  • VEX Augments Static SBOMs: While SBOMs provide a static snapshot, dynamic VEX statements are critical for providing context on exploitability, enabling more precise and efficient vulnerability remediation efforts.
  • Supplier Accountability is Paramount: A strong Third-Party Risk Management (TPRM) program, including comprehensive vetting, contractual SLAs, and structured escalation processes, is vital to hold suppliers accountable for their security posture and remediation responsiveness.
  • Transparency Builds Customer Trust: Providing customers with machine-readable SBOMs, VEX statements, and advisories empowers them to understand and manage their own risks, fostering greater confidence in the product.

About the Speaker(s)

The talk featured three key security leaders from Dell, each contributing their expertise to different facets of the vulnerability management ecosystem. Trisha led the discussion on the Dependency Management Platform (DMP), emphasizing the critical role of comprehensive inventory management and the distinction between internal inventory and external SBOMs. Her insights highlighted the journey from initial SCA tool usage to a sophisticated system driven by regulatory mandates like EO 14028. Julia focused on Third-Party Risk Management (TPRM), detailing Dell's rigorous processes for vetting and continuously monitoring suppliers, including inherent risk assessments, security due diligence, and escalation frameworks for non-compliance. Her expertise underscored the importance of holding external partners to high security standards. Finally, Cassie provided the perspective of the Product Security Incident Response Team (PERT), illustrating how PERT consumes the outputs from DMP and TPRM to achieve faster, more effective vulnerability response and enhance customer transparency through advisories and VEX statements. Together, their contributions painted a comprehensive picture of Dell's multi-faceted approach to securing its software supply chain.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured case study from Dell showing how a large enterprise stitched together dependency management, third-party risk, and PSIRT operations into a coherent vulnerability management ecosystem. The three-speaker format works — each lane (DMP, TPRM, PERT) gets a domain owner who clearly lives in it. The content is honest about operational complexity and doesn't oversell. That said, this is solidly a 'how we did it' talk for a large OEM, not novel research. The SPDX 2.3 integration, VEX lifecycle separation from SBOM, and the three-tier supplier escalation model are the most concrete contributions. Nothing here will surprise a seasoned supply chain security practitioner…

Heather Calloway (CISO) — SOLID

Dell's three-part framework for supply chain vulnerability management is operationally credible and addresses a genuinely hard problem — but the talk is structured as a program description rather than a lesson. It documents what Dell built without sufficiently confronting what it cost, what failed, or what another organization would need to do differently to replicate it. The regulatory grounding is real, the integration of DMP, TPRM, and PSIRT is mature thinking, and the VEX-over-SBOM distinction is worth making. But the absence of failure data, the limited transferability for organizations without Dell-scale resources, and the lack of any honest reckoning with what this program cannot…

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025