Overview
Syllabus
Intro
bugcrowd
why are we here?
Fast forward to 2015 CLOUD / SAAS MOBILE / BYOD
Move security as close as possible to the code and the data
DevOps as a double edged sword
DevOps rapid changes moar bugs/vulns faster
start simple, take small steps easy wins
developers have to care about their code
Code is the team's baby At least Peer Code Reviews
code style/quality reviews
everyone has to care about process
Decreasing friction between Dev and Sec
500 devs != 5 security engs
protect sales/marketing and admin staff from phishing
because.. people are the new automation
Lotsa bugs, best dev training
which types of issues, in which parts, of which applications
Accelerate Security ROI
reproduceable & testable production server configurations
deliberate small "simulated" fires
The best indicator of the next bug is the last bug.
+ Small steps mean easy wins * Developers have to care about code * Security is a process, not a product Don't wait for a fire to hire fire fighters * Crowd sourcing can augment your team
Taught by
Bugcrowd