Mastering DevSecOps: Building & Testing for Security with Josh Abrahamsen

  Рет қаралды 418

The Test Automation Experience

The Test Automation Experience

Күн бұрын

Пікірлер: 4
@ciaragraham8460
@ciaragraham8460 7 ай бұрын
This was a really good video, thank you for sharing. It’s very important for teams to consider incorporating multiple layers of application security testing into the delivery pipelines. One additional thing to consider may to include a team of 'ethical hackers' into your path to production too. Similar to exploratory testing, ethical hacking is a manual effort, but can be a valuable additional layer of security to have.
@test-automation-experience
@test-automation-experience 7 ай бұрын
Thanks for your feedback! How do we convince decision makers to include ethical hacking in our project?
@ciaragraham8460
@ciaragraham8460 7 ай бұрын
That's a good question and it comes down to convincing decision makers of the value proposition. A lot vendors in the appsec space tend to use fear as a motivating factor, which can bear fruit as no one wants to be the leader who cut corners with security and then experienced a hack. However, a more positive model could be better for long-term delivery of value. There's plenty of evidence and case studies around the benefits of ethical hacking within software development lifecycle, as it really fills the gap in terms of vulnerability detection from the scanning tools and how the 'black hat' hackers operate. The various bug bounty initiatives that many companies run are good examples of an ‘open-sourced’ model, both these can be expensive to operate with the potential of large payouts and operate at the speed of the individual security researchers, not the speed of your development team.@@test-automation-experience
@ciaragraham8460
@ciaragraham8460 7 ай бұрын
That's a good question and it comes down to convincing decision makers of the value proposition. A lot vendors in the appsec space tend to use fear as a motivating factor, which can bear fruit as no one wants to be the leader who cut corners with security and then experienced a hack. However, a more positive model could be better for long-term delivery of value. There's plenty of evidence and case studies around the benefits of ethical hacking within software development lifecycle, as it really fills the gap in terms of vulnerability detection from the scanning tools and how the 'black hat' hackers operate. The various bug bounty initiatives that many companies run are good examples of an ‘open-sourced’ model, both these can be expensive to operate with the potential of large payouts and operate at the speed of the individual security researchers, not the speed of your development team.@@test-automation-experience
Revolutionize Your Software Dev with Replay.io: A Deep Dive with Filip Hric
51:27
The Test Automation Experience
Рет қаралды 318
My 16 Years of Automation Mistakes In 21 Minutes
21:42
The Test Automation Experience
Рет қаралды 474
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 14 МЛН
Help Me Celebrate! 😍🙏
00:35
Alan Chikin Chow
Рет қаралды 86 МЛН
Кәсіпқой бокс | Жәнібек Әлімханұлы - Андрей Михайлович
48:57
Node.js Security Best Practices: JWT blacklisting, rate limiting, schema validation
12:02
Top 5 Software Testing Trends of 2024 ⚡️
10:15
Execute Automation
Рет қаралды 24 М.
Debunking 7 Biggest Automated Testing Myths
22:50
The Test Automation Experience
Рет қаралды 394
DevSecOps: Mastering Security in Software Development
6:52
Building Responsive Layouts with @media
22:23
Prof. Obetz
Рет қаралды 161
What is DevSecOps? | DevOps vs DevSecOps | KodeKloud
8:50
KodeKloud
Рет қаралды 6 М.
Когда отец одевает ребёнка @JaySharon
00:16
История одного вокалиста
Рет қаралды 14 МЛН