YoVDO

From Gates to Guardrails - Alternate Approaches to Product Security

Offered By: LASCON via YouTube

Tags

LASCON Courses Regulatory Compliance Courses Security Automation Courses

Course Description

Overview

Explore a conference talk from LASCON's Rugged DevOps Track that challenges traditional secure development lifecycles. Discover how Netflix approaches product security in the age of DevOps, agile methodologies, cloud computing, and continuous delivery. Learn about practical methods for addressing continuous assessment, regulatory compliance, and team staffing in fast-paced technology environments. Gain insights into Netflix's unique culture, visibility practices, and automated security tools like Security Monkey. Understand the shift from gate-based security models to more dynamic, pragmatic approaches that align with modern development practices and business needs.

Syllabus

Intro
National Recreation Area
Traditional Security Model
Netflix
Speed and Scale
Thesis
Culture
Visibility
Netflix Environment
UI Interoperability
Amazon Region
Netflix Culture
DevOps Culture
Responsible Disclosure Program
Recruiting
Sprints
Security with Operations
Cloud HSM Dashboard
Email Alert Configuration
Chronos
NSA
MimiR
Automation
Security Monkey
Configuration History
Summary
Engagement Model


Taught by

LASCON

Related Courses

Comparing WAF and RASP - Why?
LASCON via YouTube
API Security - Is it the New Application Attack Surface and How to Secure at Enterprise Scale
LASCON via YouTube
Privacy Impact Assessments - How Much Privacy Is Enough?
LASCON via YouTube
Your Frontier Defense - Understanding Web Application Firewalls
LASCON via YouTube
Doing This One Crazy Thing Will Change Your AppSec Program Forever
LASCON via YouTube