Building a sustainable security requirements process with the ASVS - Josh Grossman - NDC Security

  Рет қаралды 1,077

NDC Conferences

NDC Conferences

Жыл бұрын

Shift left? Spread left? Regardless of terminology, we want to be thinking about security earlier on in the development lifecycle. Ideally whilst we are still gathering the business requirements.
But how do we do that? Not everyone can think up security requirements on demand and we need to do this constantly for each new feature or development.
As a project lead for the OWASP Application Security Verification Standard (ASVS), a list of requirements for building secure software, this is something I have spent time working on as well as discussing with a variety of development teams. In this talk I want to show you what we came up with.
After a brief overview of what the ASVS is, we will then talk about how to:
- Get buy-in for security at this stage
- Balance trade-offs and prioritize different security requirements
- Trim the ASVS to focus on your current context
- Make the process repeatable and maintain a view of security state
You should leave the talk with not only a better understanding of the ASVS but also clear ideas on how you can take this and implement it as part of your own organization's requirements process.
Check out our new channel:
NDC Clips:
‪@ndcclips‬
Check out more of our featured speakers and talks at
ndcconferences.com/
ndc-security.com/

Пікірлер
OWASP ASVS Project - Josh Grossman
54:51
OWASP Foundation
Рет қаралды 1 М.
孩子多的烦恼?#火影忍者 #家庭 #佐助
00:31
火影忍者一家
Рет қаралды 18 МЛН
Tom & Jerry !! 😂😂
00:59
Tibo InShape
Рет қаралды 58 МЛН
The day of the sea 🌊 🤣❤️ #demariki
00:22
Demariki
Рет қаралды 91 МЛН
"I Hate Agile!" | Allen Holub On Why He Thinks Agile And Scrum Are Broken
8:33
Jeevan Singh -- The Future of Application Security Engineers
46:59
The Application Security Podcast
Рет қаралды 2,2 М.
OWASP ASVS: Unlocking Stronger Application Security
32:15
Bishop Fox
Рет қаралды 536
Economist explains why India can never grow like China
23:47
Money & Macro
Рет қаралды 318 М.
Why Does Scrum Make Programmers HATE Coding?
16:14
Thriving Technologist
Рет қаралды 497 М.
From the OWASP Top Ten(s) to the OWASP ASVS - Jim Manico
1:01:47
NDC Conferences
Рет қаралды 11 М.
Security By Design Decision
27:00
S4 Events
Рет қаралды 2,1 М.
YOTAPHONE 2 - СПУСТЯ 10 ЛЕТ
15:13
ЗЕ МАККЕРС
Рет қаралды 123 М.
Gizli Apple Watch Özelliği😱
0:14
Safak Novruz
Рет қаралды 4,6 МЛН
Телефон в воде 🤯
0:28
FATA MORGANA
Рет қаралды 1,2 МЛН
Low Price Best 👌 China Mobile 📱
0:42
Tech Official
Рет қаралды 717 М.
iPhone 12 socket cleaning #fixit
0:30
Tamar DB (mt)
Рет қаралды 54 МЛН