Главная
Study mode:
on
1
Intro
2
Lead Security Architect Cabinet Office UK Government
3
Certification Accreditation PCI ISO27001
4
Change control boards
5
Agile changes everything
6
Individuals and interactions over processes and tools
7
Working software over comprehensive documentation
8
Responding to change over following a plan
9
Customer collaboration over contract negotiation
10
Contracts, Planning, Documentation, Processes and Tools
11
Building software together
12
Maximising work not done
13
Minimum viable product or service
14
Protect personal data
15
Security design principles
16
8 Principles of risk management
17
Accept uncertainty Security as part of the team Understand the risks
18
Trust decision making Security is part of everything User experience is important
19
Audit decisions Understand big picture impact
20
How does agile help?
21
Continual delivery of business value
22
Security must be an enabler of the team
23
Safety engineering and security engineering
24
The unit of delivery is the team
25
The unit of decision making is the team
26
Educate the team to the threats
27
Keep a running risk log
28
Apply risk decisions per story
29
Apply controls per story
30
Security debt
31
Choosing the secure method must be the easiest option
32
Dealing with patches
33
Updating machines in test
34
Automated Testing
35
Fast repeatable deploys
36
Code review of infrastructure changes
37
Application whitelisting
38
Minimise administrative controls
Description:
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only! Grab it Explore a conference talk that delves into the intersection of agile methodologies and secure system design. Learn how agile practices can lead to more securely designed and operated systems, despite common misconceptions. Discover the speaker's perspective as a Senior Technical Architect at The Government Digital Service on balancing agility and security. Gain insights into key agile principles, security design principles, and risk management strategies. Understand how to integrate security into agile teams, maintain a running risk log, apply controls per story, and manage security debt. Explore practical approaches to choosing secure methods, dealing with patches, automated testing, and application whitelisting. This talk challenges traditional views on security in agile environments and provides actionable strategies for creating robust, secure systems while maintaining agility.

Rugged - Being Secure and Agile

GOTO Conferences
Add to list
0:00 / 0:00