WHAT ARE THE CHALLENGES THAT AGILE / DEVOPS / LEAN POSE TO INFOSEC?
3
INSTEAD, EXAMINE HOW ADOPTING THESE STRATEGIES CAN HELP YOU WIN
4
LEAN SECURITY IS FOR WINNERS
5
SECURITY IS JUST BEANCOUNTING
6
WE TRADED ENGINEERING FOR ACTUARIAL DUTIES
7
A SECURITY MANAGEMENT SYSTEM PROVIDES OPTIMAL VALUE TO THE ORGANIZATION FIE ACTIVELY SUPPORTS ACHIEVING THE BUSINESS AND COMPLIANCE OBJECTIVES OF THE ORGANIZATION (THE VARIABLE PART) IS AN EFFICIENT,…
8
SECURITY IS A BOTTLENECK
9
UNDERSTAND THE WASTE THAT YOU GENERATE
10
SECURITY IS INVISIBLE
11
SECURITY PROFESSIONALS ARE QUICK TO SAY SECURITY IS EVERYONE'S JOB
12
SECURITY IS ALWAYS TOO LATE
13
CEASE DEPENDENCE ON MASS INSPECTION TO ACHIEVE QUALITY. IMPROVE THE PROCESS AND BUILD QUALITY INTO THE PRODUCT IN THE FIRST PLACE.'
14
SECURITY IS ALWAYS IN THE WAY
15
SECURITY IS PERFECTIONIST AND IS THEREFORE UNREALISTIC
16
SECURITY IS YOUR PRODUCT
17
QUESTIONS?
Description:
Explore lean security principles in this 42-minute LASCON conference talk by Ernest Mueller. Learn how to align security practices with Lean, DevOps, and Continuous Delivery philosophies to enhance organizational speed and efficiency. Discover strategies for implementing attack-driven approaches to software delivery pipelines, increasing transparency and visibility across the organization. Gain insights into defensive systems thinking to reshape the attack landscape while working in harmony with business functions. Understand emerging Lean, Agile, and DevOps techniques, acquire organizational strategies to bridge DevOps and security, and learn to apply effective detection and monitoring through real-world examples. Examine common security challenges and misconceptions, and discover how adopting lean security principles can transform security from a bottleneck to a valuable, integrated process that supports business objectives while efficiently managing risks.