Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

AppSec++ - Taking the Best of Agile, DevOps, and CI/CD into Your AppSec Program

OWASP Foundation via YouTube

Overview

Explore how to optimize your AppSec program by incorporating the best practices from Agile, DevOps, and CI/CD methodologies in this informative conference talk from AppSecUSA 2016. Learn from real-world examples and concrete strategies implemented across multiple companies, ranging from 4,000 to 40,000+ employees, to scale up your AppSec efforts and tackle technical security debt. Discover how to transform your small team of AppSec professionals into a virtual army, leveraging iterative improvements and innovative approaches. Gain insights into new OWASP projects, including the AppSec Pipeline project, Defect Dojo, and the AppSec Pipeline toolbox, which can aid in your journey towards more effective application security. Delve into topics such as custom AppSec workflows, testing automation, optimizing people's time, and fostering a culture of innovation within your organization.

Syllabus

Intro
Matts background
Custom AppSec
Henry Ford
Phoenix Project
Workflow
Testing
Burrito Your Way
AppSec Pipeline
Key Features
Pipeline
Build Pipelines
Deming Quote
Optimizing People Time
Pearson
Call to Action
Please bug all vendors
Chat integration
Automation
Culture of Innovation
Whats Next
Weaponizing Jenkins
Demo
Scale
Jenkins Pipeline
Open Source
Pipeline is Code
Open Projects
Defect Dojo
Aaron Weaver

Taught by

OWASP Foundation

Reviews

Start your review of AppSec++ - Taking the Best of Agile, DevOps, and CI/CD into Your AppSec Program

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.