Главная
Study mode:
on
1
Intro
2
COMPLIANCE
3
DIMINISHING RETURNS
4
MATURITY IS NOT SECURITY
5
AGGREGATES HIDE UNIQUENESS
6
EDUCATION IS NOT JUST TRAINING
7
PEOPLE ARE NOT MACHINES
8
OUTCOMES ARE NOT EVERYTHING
9
VERIFICATION IS NOT VALIDATION
10
WHAT TO DO NOW
Description:
Explore key insights into effective application security program management in this 25-minute conference talk from GrrCon 2016. Delve into topics such as compliance, diminishing returns, maturity versus security, the limitations of aggregates, the importance of comprehensive education beyond training, human factors in security, outcome-based approaches, and the distinction between verification and validation. Gain practical advice on improving your AppSec program and learn how to critically evaluate its effectiveness beyond traditional metrics and assumptions.

Reality Checking Your AppSec Program

Add to list
0:00 / 0:00