Главная
Study mode:
on
1
Intro
2
Go Purple! Adopt purple team strategy to augment Application Security Programs
3
Challenges
4
Application Security Program Elements
5
Blue Team vs Red team
6
Economics of fixing Security Bugs
7
Purple team (Realist)
8
Blue Team (Optimist) vs Red team (Paranoid)
9
Security within SDLC
10
Checkpoint Approach
11
Secure DevOps Approach
12
Purple Team Approach
13
Key Aspects
14
Foundations for a Positive Security Process
15
Application Security Program Ithe Purple wall
16
Application Security Program the Purple way!
17
Application Inventory
18
Engagement
19
Unrestricted File Upload
20
Blind XSS
21
Security Plan
22
Full Stack Assessment
23
Reporting
24
How do you communicate a vulnerability?
25
Remediation Consulting
26
Metrics
27
Conclusion
Description:
Explore a comprehensive conference talk on adopting a purple team strategy to enhance application security programs. Learn about the challenges faced in modern software development, including the shift to microservices and the rise of DevOps. Discover the limitations of traditional security approaches and the advantages of implementing a purple team strategy. Understand how purple teams combine defensive security controls from blue teams with exploitation techniques from red teams to create a unified security approach. Gain insights into breaking artificial boundaries, transforming security from a checkpoint to an integrated function, and improving collaboration between security professionals and developers. Examine the traits and methodology of purple teams, their influence on various groups, and how they can augment the effectiveness of application security programs. Delve into key aspects of the purple team approach, including application inventory, engagement strategies, security planning, full-stack assessment, and effective vulnerability communication. Acquire knowledge on implementing a positive security process and measuring the success of your application security program using the purple team methodology. Read more

Go Purple! Adopt Purple Team Strategy to Augment Application Security Programs

LASCON
Add to list
0:00 / 0:00