Overview
Explore current research and best practices in SecDevOps through this 51-minute conference talk from APPSEC Cali 2018. Delve into topics such as scaling security, static and dynamic analysis, security baselines, and infrastructure best practices. Learn how to calculate ROI for static analysis tools, implement effective hooks, and detect attacks. Gain insights from Clint Gibler, Research Director at NCC Group, as he shares his expertise on integrating security into Agile and DevOps processes. Discover practical approaches to dependency management, unit testing, and fostering security conversations within development teams.
Syllabus
Intro
Agile and DevOps
How to scale security
Overview
Static vs Dynamic Analysis
Types of Static Analysis
Good Hooks
Start a Conversation
Dependencies
Running arbitrary checks
Should I buy a static analysis tool
Calculating the ROI
Dynamic Analysis
Security Baselines
Unit Tests
Background
What we did
Doing this well
Infrastructure best practices
Detecting attacks
Questions
Taught by
OWASP Foundation