Главная
Study mode:
on
1
Introduction
2
Background on Dun Bradstreet
3
The team
4
Other responsibilities
5
Landscape
6
Remote team
7
Automation
8
Vulnerability scanning
9
Vulnerability metrics
10
Diverse tool set
11
Aggregated data
12
Dashboards
13
JIRA
14
JIRA Reporting
15
Automation Framework
16
Bagofholding
17
Bagofholding App
18
Report
19
Templates
20
Gamification
21
Validation
22
Lessons Learned
23
Titanic Reference
24
Rohinis Demo
25
SSC Results
26
Questions
Description:
Explore an innovative approach to automating application security assessments in this 45-minute conference talk from AppSec EU 2017. Discover how a team tackled the challenge of securing hundreds of applications across diverse programming languages, platforms, and legacy systems with limited resources. Learn about their journey in creating an automation-scanning and reporting platform using Jenkins, HP Fortify SCA/SSC, OWASP ZAP, OWASP DefectDojo, Slack, and Jira. Gain insights into their decision-making process, including technologies they chose not to use and why. Witness a live demo showcasing the implementation of this automated solution, covering topics such as vulnerability scanning, metrics, aggregated data, dashboards, and JIRA reporting. Understand the lessons learned and participate in a collaborative session where feedback and questions are encouraged.

Rise of the Machines: Automating Application Security Assessments - AppSec EU 2017

OWASP Foundation
Add to list
0:00 / 0:00