Главная
Study mode:
on
1
Intro
2
Background
3
Importance of Security
4
Solving defects early
5
Named vulnerabilities in 2016
6
Security
7
SDLC
8
Control
9
Common Framework
10
Domains
11
Verification Statements
12
Control vs Requirement
13
Security Control Types
14
B Sack
15
Questionnaire
16
Benefits
17
Questions
Description:
Explore how to integrate the OWASP Application Security Verification Standard (ASVS) into the Secure Software Development Lifecycle in this AppSecUSA 2017 conference talk. Learn strategies for implementing uniform security requirements across large organizations, prioritizing security tasks, and overcoming challenges in dispersed development teams. Discover how to leverage the ASVS to create functional and non-functional security requirements, develop a questionnaire for determining appropriate ASVS levels, and incorporate security tasks into existing development processes. Gain insights on writing test plans based on ASVS verification statements and mapping them to requirements for effective validation. Understand how this approach can streamline secure development, making it more manageable and less ambiguous for development teams.

Leveraging the ASVS in the Secure Software Development Lifecycle

OWASP Foundation
Add to list
0:00 / 0:00