Главная
Study mode:
on
1
Intro
2
usr/bin/whoami MURLO
3
What is Software Security?
4
More than just...
5
printf("Hello, World\n")
6
Early 2000s: Fix the damn cod
7
Security in a waterfall world
8
We're Agile now
9
Efforts to get real
10
Option 1: SDLC-focused
11
Option 2: Use a framework E.g. the Software Security Framework from BSIMM
12
Stakeholders & Organisation.
13
Strategy & Metrics
14
Compliance & Policy
15
Training
16
Attack Models
17
Security Features & Design
18
Standards & Requirements
19
Architecture Analysis
20
Code Review
21
Security Testing
22
Penetration Testing
23
Software Environment
24
Config Mgmt & Vuln Mgmt
25
Start small
26
Security at the speed of developme...
27
Continually improve
28
Further reading
29
Online Resources
Description:
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only! Grab it Explore the fundamentals of software security initiatives in this comprehensive NDC Oslo 2020 conference talk. Learn about the essential components of a successful AppSec program, including the right tools, activities, and culture. Discover how to balance finding, fixing, and preventing security issues in software development. Gain insights into lessons learned from two decades of software security experience and understand various techniques to address security challenges in Agile environments. Delve into SDLC-focused approaches and frameworks like the Software Security Framework from BSIMM. Examine key areas such as stakeholder management, strategy, compliance, training, attack modeling, security features, code review, testing, and vulnerability management. Get practical advice on starting small, improving continuously, and adapting security practices to match development speeds. Ideal for those looking to establish or enhance their organization's software security initiatives.

What Is a Software Security Initiative and Do I Need One

NDC Conferences
Add to list