YoVDO

Practical Tips for Web Application Security in the Age of Agile and DevOps

Offered By: OWASP Foundation via YouTube

Tags

Web Application Security Courses DevOps Courses Agile Development Courses Static Analysis Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore practical tips for web application security in the age of agile and DevOps in this 53-minute conference talk recorded at AppSecUSA 2016. Learn how to adapt traditional heavyweight security controls to lightweight efforts suitable for modern development practices. Discover techniques for obtaining visibility that enables rapid iteration, and gain insights on measuring security maturity in a non-theoretical way. Delve into topics such as static analysis, dynamic scanning, proactive alerting, and attack-driven defense. Benefit from real-world examples and experiences shared by Zane Lackey, Founder/Chief Security Officer at Signal Sciences and former Director of Security Engineering at Etsy.

Syllabus

Intro
Zanes background
What is this talk about
Clich alert
Changes in DevOps
Security is no longer outsourced
Waterfall security methodology
Core components
What pieces of this needs to change
Agenda
Static analysis
Traditional static analysis
How to adapt
Command execution
hashing encryption
proactive alerting
scanning
Dynamics gaming
Cheap use cases
Legacy visibility
Building effective visibility
Feedback legacy
Bounties
The hallmark of modern app tech
Attack driven defense
Work your way back
Data forensics
Etsy example
Closing thesis
Questions


Taught by

OWASP Foundation

Related Courses

Desarrollo y Diseño de Videojuegos: Proyecto final
Universidad de los Andes via Coursera
Web Application Development: Basic Concepts
University of New Mexico via Coursera
Agile Development in Practice (Project-centered Course)
University of Virginia via Coursera
软件工程
Peking University via Coursera
Software Engineering: Introduction
The University of British Columbia via edX