Главная
Study mode:
on
1
Intro
2
About me
3
You help securing
4
What happened?
5
COACH WITH THE END IN MIND
6
Planning phase
7
Keep in touch
8
The security coach
9
Select your elements wisely
10
Make it visible
11
Get a headstart: Get & train security teams!
12
Raise your champions
13
Don't overdo it!
14
Threatmodelling
15
Next step: automate!
16
See how & when you can let go
17
NEVER FORGET!
18
Add too many processes & steps CAUSE OF DEATH
19
Let the developer dig for requirements
20
Forget to measure
21
Do SDLC/ automation all yourself
22
Do SDLC / automation all yourself
23
Making it complex
24
Chief Excuse Officer
25
Wanting to hold on
26
Recap
Description:
Explore effective strategies for fostering sustainable security practices in DevOps and Agile environments. Learn how to empower development teams to maintain long-term security through assessment, training, and coaching. Discover techniques for automation, agile risk management, and avoiding common pitfalls. Gain insights on selecting appropriate security elements, raising security champions, and implementing threat modeling. Understand the importance of balancing processes, measuring progress, and gradually transitioning responsibility to development teams. Master the art of teaching teams to "fish" for security rather than simply providing short-term solutions.

Teaching Sustainable Security in DevOps and Agile Environments - AppSecUSA 2018

OWASP Foundation
Add to list