Moving Fast and Securing Things
Offered By: OWASP Foundation via YouTube
Course Description
Overview
Explore a conference talk from AppSecUSA 2017 that delves into balancing security processes with rapid development in startups. Learn how Slack implemented a Secure Development Lifecycle (SDL) process that accelerated development while scaling security coverage for a growing engineering team. Discover their flexible framework for security reviews, including a self-service assessment tool, checklist generator, and chat-based process. Gain insights on encouraging a security mindset among developers without creating adversarial relationships. Examine quantified success metrics and learn how to apply similar approaches in other organizations. The speakers share their experiences in product security, bug bounty programs, and security automation, offering valuable perspectives for security professionals and developers alike.
Syllabus
Intro
Slack
Transparency
SelfService STL
Checklists
Process
Security Product Channel
Feature Channel
Checklist
Checklist Feedback
Security Background
Positive Feedback
User Feedback
Real Bugs
High Grade
SPL Graph
Open Source Tools
QA Process
Taught by
OWASP Foundation
Related Courses
Building Geospatial Apps on Postgres, PostGIS, & Citus at Large ScaleMicrosoft via YouTube Unlocking the Power of ML for Your JavaScript Applications with TensorFlow.js
TensorFlow via YouTube Managing the Reactive World with RxJava - Jake Wharton
ChariotSolutions via YouTube What's New in Grails 2.0
ChariotSolutions via YouTube Performance Analysis of Apache Spark and Presto in Cloud Environments
Databricks via YouTube