Главная
Study mode:
on
1
Intro
2
Zanes background
3
What is this talk about
4
Clich alert
5
Changes in DevOps
6
Security is no longer outsourced
7
Waterfall security methodology
8
Core components
9
What pieces of this needs to change
10
Agenda
11
Static analysis
12
Traditional static analysis
13
How to adapt
14
Command execution
15
hashing encryption
16
proactive alerting
17
scanning
18
Dynamics gaming
19
Cheap use cases
20
Legacy visibility
21
Building effective visibility
22
Feedback legacy
23
Bounties
24
The hallmark of modern app tech
25
Attack driven defense
26
Work your way back
27
Data forensics
28
Etsy example
29
Closing thesis
30
Questions
Description:
Explore practical tips for web application security in the age of agile and DevOps in this 53-minute conference talk recorded at AppSecUSA 2016. Learn how to adapt traditional heavyweight security controls to lightweight efforts suitable for modern development practices. Discover techniques for obtaining visibility that enables rapid iteration, and gain insights on measuring security maturity in a non-theoretical way. Delve into topics such as static analysis, dynamic scanning, proactive alerting, and attack-driven defense. Benefit from real-world examples and experiences shared by Zane Lackey, Founder/Chief Security Officer at Signal Sciences and former Director of Security Engineering at Etsy.

Practical Tips for Web Application Security in the Age of Agile and DevOps

OWASP Foundation
Add to list
0:00 / 0:00