Главная
Study mode:
on
1
Introduction
2
Agenda
3
The Tunnel
4
Application Portfolios
5
Challenges
6
Continuous Program Approach
7
Application Profiling Components
8
Assessment Strategy
9
What Fits Our Organization
10
Design Enablement
11
Reference Architecture
12
Analysis Metrics
13
DevOps Integration
14
Questions
Description:
Explore a comprehensive strategy for implementing a continuous Application Security (AppSec) program in this 46-minute conference talk from AppSecUSA 2017. Learn how to unify disparate security initiatives, address full application portfolio coverage, and enable high-paced development paradigms like DevOps and CI/CD. Discover a model that ties together threat modeling, code reviews, and penetration tests with business and risk processes to enhance development efficiency. Understand how to leverage OWASP SAMM principles, enable continuous improvement, and implement the program incrementally. Gain insights on prioritizing security initiatives, managing risks, and empowering application teams to advocate for security practices. Leave with actionable strategies to transform your AppSec approach and juggle the elephants of enterprise application security effectively.

Juggling the Elephants - Making AppSec a Continuous Program

OWASP Foundation
Add to list