Главная
Study mode:
on
1
Agenda
2
Questions
3
Example
4
The best approach
5
Application security dimensions
6
Framework
7
Processes
8
Testing
9
Team
10
Security
11
Standard
12
Big picture
13
Assessment results
14
Independent software vendor
15
Facebook
16
Comcast
17
PCI
18
Why your reports are dead
19
Why your reports are there
20
Why it works
21
Benefits
22
Vendor requirements
23
Presentation testing
24
Certificate of achievement
25
Conclusion
26
QA
27
Trade off
Description:
Explore the evolution of software security verification in this 31-minute OWASP Global AppSec Tel Aviv conference talk. Discover the OWASP Software Security 5D Framework and examine assessment data from various international companies. Learn how security practices have progressed from static reports to integrated lifecycle management of security bugs. Gain insights from Matteo Meucci, CEO and co-founder of Minded Security, as he shares his extensive experience in Application Security and his contributions to OWASP projects. Delve into topics such as application security dimensions, processes, testing, team dynamics, and industry standards. Understand why traditional security reports are becoming obsolete and explore more effective approaches to software security. Examine case studies from major companies and discuss the benefits and challenges of modern security practices. Conclude with a Q&A session addressing the trade-offs in implementing comprehensive software security measures.

Software Security 5D Framework - Evolution of Security Verification

OWASP Foundation
Add to list
0:00 / 0:00