Главная
Study mode:
on
1
Intro
2
Disclaimer
3
Agenda
4
Tejas Intro
5
Andrew Intro
6
Sanjeev Intro
7
Who is this talk for
8
Challenges
9
Overview
10
Product Security Goals
11
Typical Scenario
12
Engagement Model
13
Product Security
14
High Touch Engagement
15
Low Touch Engagement
16
Hybrid Model
17
Brainstorm
18
Product Context
19
Technical Needs
20
Demo
21
Demo Walkthrough
22
Custom Security Controls
23
Tooling Documentation
24
Summary
Description:
Discover how to scale security assessments and provide timely feedback in hyper-growth organizations through context-based security assessment workflows. Learn from Splunk's Senior Tooling and Automation Engineer Andrew Lien, Product Security Tooling Engineer Sanjeev Reddy, and Teja Myneedu as they demonstrate their innovative approach to streamlining processes and automating workflows for product security teams. Explore the concept of a "magical funnel" that captures product context to determine appropriate security assessment workflows, eliminating repetitive information gathering and improving efficiency for both security and engineering teams. Gain insights into Splunk's method of scaling security assurance by creating custom assessment workflows based on security impact and retaining context for future assessments. This 43-minute OWASP Foundation talk covers challenges faced by product security teams, engagement models, product context considerations, and includes a demo of their solution, making it valuable for professionals seeking to enhance their organization's security assessment processes. Read more

Scaling Security through Context-Based Security Assessments

OWASP Foundation
Add to list
0:00 / 0:00