Главная
Study mode:
on
1
Introduction
2
Who is this for
3
What is security
4
What is strategy
5
Risk
6
Security Outcomes
7
Incentive Alignment
8
Security is not about computers
9
Exposure tolerance
10
Maturity level
11
Tech debt
12
Brooks law
13
Compliance
14
Governance
15
Metrics
16
Blameless Engineering
17
Designing for Human Error
18
Teach Systems Literacy
19
Responsibility for Security
20
Do not be a gatekeeper
21
Engineering principles
22
Capability is a liability
23
Two different systems architectures
24
QA matters
25
Hiring vs consulting
26
Buying security
27
Threat intelligence
28
Platform choices
29
Separation of concerns
30
Segmentation
31
Redeploy
32
Autoscaling
33
Trust Chaining
34
Automation
35
Observability
36
Legal
37
Security Books
38
Questions
Description:
Explore a comprehensive strategy for implementing effective security measures in small to medium-sized development teams through this insightful conference talk by Eleanor Saitta. Gain valuable insights on how to approach security as a collective responsibility, develop a unified strategy, and coordinate efforts across the organization. Learn why starting with technical work is important, but not sufficient, and discover how to teach teams to view security as a whole-systems outcome. Delve into topics such as risk assessment, cost considerations, security compliance, staffing, and when to engage consultants. Understand the relationship between security and other organizational aspects, and acquire practical tools to enhance your team's security posture. Whether you're an engineering director, a startup's first security hire, or a consultant, this talk provides essential guidance on building a robust security framework for your development team.

On Strategy

Cooper
Add to list