Главная
Study mode:
on
1
Intro
2
Agenda
3
GDPR
4
What is personal data
5
GDPR principles
6
Confidentiality
7
Software Development Lifecycle
8
Secure Development Lifecycle
9
Strategy Metrics
10
Policy in Compliance
11
Education and Guidance
12
Data Privacy Impact Assessment
13
Security Requirements
14
Security Architecture
15
Design Review
16
Implementation Review
17
Dynamic Testing
18
Data Breach Reporting
19
Environment Hardening
20
Operational Enablement
21
Customer Example
22
What We Like
23
Advantages
24
Community
25
Next steps
26
Questions
27
Contact
Description:
Explore a comprehensive conference talk on embedding GDPR requirements into the Secure Development Lifecycle (SDLC). Learn how to map GDPR principles to software security activities, including involving the Data Protection Officer in governance, providing privacy awareness training to developers, and incorporating privacy considerations into secure coding guidelines. Discover techniques for conducting Privacy Impact Analysis as part of risk assessment, translating GDPR into software security requirements, and applying privacy by design in software architecture. Gain insights on integrating privacy threats into threat modeling, implementing privacy security checklists in testing, and adapting vulnerability and incident management processes to meet GDPR-specific breach notification requirements. Benefit from practical implementation aspects and real-life use case demonstrations from software security and privacy projects.

Embedding GDPR Into the Secure Development Lifecycle

OWASP Foundation
Add to list
0:00 / 0:00