Главная
Study mode:
on
1
Intro
2
DevOps
3
Actual Problem Ignored
4
Fantasy Campaign Setting
5
CI/CD Pipeline
6
Communication
7
Risks
8
Empathy
9
Codes of Conduct
10
RPG Threat Models
11
RPG Interpersonal Skills
12
A Fiendish Folio
13
Monstrously Manual
14
Weary of Awareness
15
Meaningful Metrics
16
Improving Fix Verification
17
Unearthing Arcana
18
Manual of the Planes
19
Cognitive Biases
20
Mind Flayer
21
Tough 10(-ish) List
22
Continuous Integration
23
Continuous Deployment
Description:
Explore the human-centric approach to DevSecOps in this 48-minute conference talk from APPSEC Cali 2018. Delve into the critical role of people in integrating security into DevOps practices, moving beyond automation to focus on collaboration, communication, and relationship-building. Learn techniques for establishing incentives, encouraging participation, providing constructive feedback, and achieving team goals. Discover how to use metrics and communication effectively to drive positive behaviors in security implementation. Gain insights into managing constraints like time, budget, and resources while navigating trade-offs in real-world application security scenarios. Understand the importance of developing skills in informed decision-making and influencing peers to grow a successful career in AppSec. Through analogies to RPG concepts and exploration of cognitive biases, grasp the complexities of security integration in DevOps environments and the strategies to overcome them.

DevSecOps: Integrating People and Automation in Application Security

OWASP Foundation
Add to list
0:00 / 0:00