Главная
Study mode:
on
1
Introduction
2
Denim Group
3
Bruce Schneier
4
AppSec vs Developer Training
5
Training is one of those sacred cows
6
Background on the project
7
Lack of workforce analytics
8
Research
9
Have You Had Any Training
10
How We Did It
11
Three Big hypotheses
12
Sample questions
13
prescriptive questions
14
results
15
gap between awareness and prescriptive
16
sample fatigue
17
weird results
18
technology companies
19
no prior secure coding
20
How Developers Learn
21
Asynchronous Learning
22
Dont Ignore the Basics
23
Incentives Matter
24
Conclusions
25
Whats next
Description:
Explore the effectiveness of AppSec training for developers in this 33-minute OWASP Foundation conference talk. Dive into the results of a yearlong survey of nearly 1,000 software developers, assessing their application security knowledge before and after formal training. Examine the survey methodology, which includes developers from various backgrounds and industries, and discover the surprising findings from a "retest" of a subset of respondents. Learn about the gap between security awareness and prescriptive knowledge, the impact of sample fatigue, and unexpected results from technology companies. Gain insights into how developers learn, the importance of asynchronous learning, and the role of incentives in security training. Understand the implications of these findings for application risk managers and those relying on training as part of their application security strategy.

Can AppSec Training Really Make Developers Security-Smart?

OWASP Foundation
Add to list
0:00 / 0:00