Главная
Study mode:
on
1
Introduction
2
Being the only member of the security team
3
What responsibilities I had
4
How much work is involved
5
What was up against me
6
Technical strategies
7
Push left
8
Writing code
9
Automating
10
Code Analysis
11
Vulnerability Management
12
Pentesting
13
Bug Bounty
14
Cultural Strategies
15
Key Stakeholders
16
Everything is okay
17
Be authentic
18
Be accessible
19
Teach different classes
20
When all of this works
21
Example
22
Not clicking on phishing emails
23
Working with engineers
24
Its not easy
25
Technical perspective
26
Cultural perspective
27
Being powerful while powerless
28
Conclusion
29
Does this work yet
30
Dealing with conflict
31
Premise or cloud
32
Difficult players
33
Managing priorities
Description:
Explore strategies for elevating security by leading without authority in this 39-minute OWASP Foundation conference talk. Discover how to be powerful while powerless as the sole member of a security team, tackling extensive responsibilities and challenges. Learn technical approaches such as shifting left, writing code, automating processes, and implementing vulnerability management. Gain insights into cultural strategies, including identifying key stakeholders, maintaining authenticity, and teaching diverse classes. Examine real-world examples of success, like reducing phishing email clicks and collaborating effectively with engineers. Address the complexities of security leadership, including conflict resolution, priority management, and navigating difficult situations in both on-premises and cloud environments.

Being Powerful While Powerless - Elevating Security By Leading Without Authority

OWASP Foundation
Add to list
0:00 / 0:00