Главная
Study mode:
on
1
Intro
2
The Status Quo of Software Development Lifecycles
3
Understanding Stakeholders and Existing Processes
4
Project Managers are EPIC assets
5
QA and DevOps
6
Customers/End-Users
7
Analyzing existing processes
8
Document the gap analysis
9
How does security affect the stakeholder?
10
How does security affect the process?
11
Preparing for rebuilding the program
12
Key program metrics
13
Important metrics
14
Phased goals
15
Goal phases
16
Gaining management support
17
Planning requirements
18
Active stakeholder participation
19
Working as a unified team
20
The importance of collaborating as one team
21
Discussions, not just bug submissions • Detailed meetings to discuss findings from offensive testing
22
Rotating work assignments and embedded liaisons
23
Setting expectations for stakeholders
24
Using organizational policy to create a need
25
Using compliance to create a need
26
The development style guide and standard libs
27
Style guides
28
Automated code scanning vs Manual reviews
29
Checklists set and track expectations
30
Conclusion
31
This talk is based on my O'REILLY repart available through Safari Books Online
Description:
Explore the intricacies of secure software development in this comprehensive ShowMeCon 2018 conference talk. Delve into the current state of software development lifecycles and learn how to identify, address, and manage security vulnerabilities throughout the process. Gain insights on understanding stakeholders, analyzing existing processes, and conducting gap analyses. Discover the importance of key program metrics, phased goals, and management support in rebuilding secure development programs. Learn strategies for effective collaboration, including rotating work assignments and embedded liaisons. Understand how to leverage organizational policies and compliance requirements to create a need for security measures. Examine the role of style guides, automated code scanning, and manual reviews in maintaining secure coding practices. Based on the speaker's O'Reilly report, this talk provides valuable knowledge for improving the security of software development lifecycles.

The Insecure Software Development Lifecycle - How to Find, Fix, and Manage

Add to list
0:00 / 0:00