Главная
Study mode:
on
1
Intro
2
About Matt
3
About OWASP
4
Whats the problem
5
Traditional software
6
Adapt
7
Its time to bury traditional AppSec
8
The old way
9
Waterfall
10
DevOps
11
Bend
12
Three Ways of DevOps
13
Workflow
14
AppSec Pipeline
15
Key Features of AppSec Pipeline
16
Optimizing is an Illusion
17
Key Goals
18
Intake
19
Pipeline End
20
Pipeline Visibility
21
Work Flow
22
Retest
23
Practice
24
Localization
25
Improved Feedback
26
Embracing Failure
27
Findings Directly Into Bugs
28
SLA
29
Puppetsible
30
Configuration Management Tools
31
Post Employment Hook
32
Turning Vulnerabilities And Its Head
33
Automate
34
Gauntlet
Description:
Explore key insights from DevOps practices and their application to Application Security in this 45-minute conference talk from AppSecEU 2015 in Amsterdam. Delve into the challenges of traditional software development and learn how to adapt AppSec methodologies for the modern era. Discover the Three Ways of DevOps and how they can be applied to create an effective AppSec Pipeline. Examine key features and goals of an AppSec Pipeline, including intake processes, visibility, workflow optimization, and improved feedback mechanisms. Learn strategies for embracing failure, automating processes, and integrating security findings directly into bug tracking systems. Gain practical knowledge on implementing configuration management tools and post-employment hooks to enhance security practices. Understand how to leverage DevOps principles to transform vulnerability management and streamline AppSec workflows for more efficient and effective security outcomes.

Lessons From DevOps - Taking DevOps Practices Into Your AppSec Life

OWASP Foundation
Add to list
0:00 / 0:00