Главная
Study mode:
on
1
Introduction
2
Fast Food
3
Instrumentation
4
AppSec Fast Food
5
AppSec Pipeline
6
What does your front door look like
7
Google Form
8
Minimal Viable Product
9
Team Choice
10
Python
11
Bag of Holding
12
What does BO do
13
The Goal
14
Metadata
15
Tag
16
Pending Engagement
17
Environment Details
18
Related People
19
Commenting
20
Search By Application
21
Length Of Activities
22
Stories
23
Social Feed
24
Tooling Vendors
25
API
26
UI API
27
Workflows
28
Generic API
29
Scanning
30
Automation
31
Assessment Schedule
32
AppSec Bot
33
ThreadFix Example
34
Checkmarks Example
35
Make AppSec Work
36
Open Source
37
Response Time
38
Developers
39
Security Requirements
40
Automatic Retests
41
Deployment Experience
42
Threat Fixjira Integration
43
Deduping
Description:
Explore a conference talk from AppSecEU 2015 in Amsterdam where Aaron Weaver presents strategies for building an AppSec pipeline to streamline security programs and maintain sanity. Learn about instrumenting fast food-style AppSec processes, creating a minimal viable product, and implementing tools like Google Forms and Python for efficient security management. Discover how to organize metadata, tag engagements, and utilize APIs for improved workflow. Gain insights into automating scanning, scheduling assessments, and integrating with development tools like Jira. Understand the importance of open source solutions, response time optimization, and automatic retests in creating an effective AppSec pipeline that enhances developer experience and addresses security requirements.

Building an AppSec Pipeline - Keeping Your Program, and Your Life, Sane

OWASP Foundation
Add to list
0:00 / 0:00