YoVDO

Moving Fast and Securing Things

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Application Security Courses

Course Description

Overview

Explore a conference talk from AppSecUSA 2017 that delves into balancing security processes with rapid development in startups. Learn how Slack implemented a Secure Development Lifecycle (SDL) process that accelerated development while scaling security coverage for a growing engineering team. Discover their flexible framework for security reviews, including a self-service assessment tool, checklist generator, and chat-based process. Gain insights on encouraging a security mindset among developers without creating adversarial relationships. Examine quantified success metrics and learn how to apply similar approaches in other organizations. The speakers share their experiences in product security, bug bounty programs, and security automation, offering valuable perspectives for security professionals and developers alike.

Syllabus

Intro
Slack
Transparency
SelfService STL
Checklists
Process
Security Product Channel
Feature Channel
Checklist
Checklist Feedback
Security Background
Positive Feedback
User Feedback
Real Bugs
High Grade
SPL Graph
Open Source Tools
QA Process


Taught by

OWASP Foundation

Related Courses

Building Geospatial Apps on Postgres, PostGIS, & Citus at Large Scale
Microsoft via YouTube
Unlocking the Power of ML for Your JavaScript Applications with TensorFlow.js
TensorFlow via YouTube
Managing the Reactive World with RxJava - Jake Wharton
ChariotSolutions via YouTube
What's New in Grails 2.0
ChariotSolutions via YouTube
Performance Analysis of Apache Spark and Presto in Cloud Environments
Databricks via YouTube