YoVDO

Making Security Approachable for Developers and Operators

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses APIs Courses Data Protection Courses Secret Management Courses Policy-as-Code Courses

Course Description

Overview

Explore a conference talk from AppSecUSA 2018 that addresses the challenge of making security more accessible to developers and operators. Learn how to apply best practices and integrate security into DevOps processes through APIs, secure-by-default platforms, and policy as code. Discover strategies for simplifying complex security concepts, moving beyond the traditional "castle and moat" model, and implementing a zero-trust approach. Gain insights into secret management, data protection, and traffic authentication/authorization. Examine the division of labor between security teams and developers, and understand how to effectively educate practitioners on security principles. Delve into the evolution of security concerns in modern application development and operations.

Syllabus

Intro
Security Mindset
Castle & Moat Security
Castle & Moat Mentality
Network Teams
Operations Teams
Castle & Moat Model
Consider: Network Integrity
Castle & Moat in Practice
Zero Trust Model
Secret Management
Data Protection
Traffic AuthN / Authz
Complexity of Security
Java 7: Cipher Class Documentation
Java Documentation
Path Forward
Splitting the Problems
Platform Layer
Application Middleware
Vault for Cryptographic Offload
Frameworks
Application Logic
Division of Labor
Security Teams
Developer Teams
Practitioner Education
Teaching Security
Traditional Security
Growing Application Concerns


Taught by

OWASP Foundation

Related Courses

Managing Resources with Azure Policy
LinkedIn Learning
Infrastructure-as-Code Security: Why, What, and How
Pluralsight
12 Essential Requirements for Policy Enforcement and Governance with OSCAL
CNCF [Cloud Native Computing Foundation] via YouTube
Application Code of Conduct - Full-Stack Policy as Code
Linux Foundation via YouTube
Bridging Security and Reality with Open Policy Agent
Linux Foundation via YouTube