Overview
Syllabus
Intro
A little About Me
Learning Objectives
Security Intricacies Don't Make Sense To Users - Type 1
Security is Not Interesting to the Regular User
Barriers to Necessary Workflow
Differing Views of Security
Put on your "User" Hat
P2: Secure Defaults Only ctd.
Display Targeted Risk Information for Security Config
Assist your User with Pre-configured Security Levels
Design to Scale (Zero-Touch Device Provisioning Example)
Do Not Allow Passive or Transitive Authorization
Implement Runtime Anomaly Detection & Device Health Checks
Ensure lot Admins Can Seamlessly Revoke Previously Granted Authority Ctd.
Just Keep Secrets Secret
Monitor Circumvention of Security Controls
In closing, Aim for Clarity & Simplicity
My Social Networking
Taught by
OWASP Foundation