Главная
Study mode:
on
1
Intro
2
Security Mindset
3
Castle & Moat Security
4
Castle & Moat Mentality
5
Network Teams
6
Operations Teams
7
Castle & Moat Model
8
Consider: Network Integrity
9
Castle & Moat in Practice
10
Zero Trust Model
11
Secret Management
12
Data Protection
13
Traffic AuthN / Authz
14
Complexity of Security
15
Java 7: Cipher Class Documentation
16
Java Documentation
17
Path Forward
18
Splitting the Problems
19
Platform Layer
20
Application Middleware
21
Vault for Cryptographic Offload
22
Frameworks
23
Application Logic
24
Division of Labor
25
Security Teams
26
Developer Teams
27
Practitioner Education
28
Teaching Security
29
Traditional Security
30
Growing Application Concerns
Description:
Explore a conference talk from AppSecUSA 2018 that addresses the challenge of making security more accessible to developers and operators. Learn how to apply best practices and integrate security into DevOps processes through APIs, secure-by-default platforms, and policy as code. Discover strategies for simplifying complex security concepts, moving beyond the traditional "castle and moat" model, and implementing a zero-trust approach. Gain insights into secret management, data protection, and traffic authentication/authorization. Examine the division of labor between security teams and developers, and understand how to effectively educate practitioners on security principles. Delve into the evolution of security concerns in modern application development and operations.

Making Security Approachable for Developers and Operators

OWASP Foundation
Add to list
0:00 / 0:00