Overview
Syllabus
Introduction
Government Digital Service
The state of information security in 2015
Approval to operate
Accreditation
Certification
Traditional model
Agile changes everything
Focus on flow and cycle time
A security nightmare!
A brave new world for security
Security needs to be an enabler
Biggest consistent finding?
Principles over rules
The UK Government published 8 principles
Accept uncertainty
Security as part of the team
Understand the risks
Trust decision making
Security is part of everything
User experience is important
Audit decisions
Understand big picture impact
Choose security model that's appropriate
Understand the threats
Educate decision makers to risks
Make risk decisions, per story, in the team
What do you do about it?
Transfer
Mitigate
Deter, Detect, Prevent
Reactive countermeasures
Correct, Respond, Recover
Traditional security people understand this
Misuse cases
Attack trees
Red teams
Automated penetration testing
Automated Integrated Repeatable
Taught by
GOTO Conferences