Главная
Study mode:
on
1
Intro
2
The Phoenix Project
3
Workflow
4
Flow Rate
5
Repeatable
6
Scripts
7
Defects
8
Local Optimization
9
Burrito analogy
10
AppSec Pipelines
11
Knapsack Workflow
12
Key Features
13
AppSec Pipeline
14
AppSec Intake
15
Pipeline Testing
16
Why do we like pipelines
17
What does Bo do
18
Software Activities
19
Improve Feedback
20
Ask the Bot
21
Culture of Innovation
22
OS Project
Description:
Explore strategies for scaling application security in large organizations through this conference talk from LASCON 2015. Learn how to leverage DevOps, Agile, and CI/CD principles to transform a small AppSec team into a virtual army capable of handling extensive application portfolios. Discover real-world experiences from Rackspace and Pearson, covering key principles for accelerating and scaling AppSec programs. Gain insights into practical implementations, including rapid static scanning provisioning, 24/7 remediation advice for developers, and efficient report generation. Delve into topics such as automation, orchestration, ChatOps, and AppSec Pipelines to address technical security debt proactively. Understand concepts like workflow optimization, defect management, and the importance of creating a culture of innovation in AppSec. Learn how to improve feedback loops, implement "Ask the Bot" systems, and explore open-source project opportunities to enhance your organization's application security capabilities. Read more

Doing AppSec at Scale - DevOps + Agile + CI/CD == AppSec Pipelines

LASCON
Add to list
0:00 / 0:00