Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Becoming a Security-Conscious Company (CHCon 20...

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
Avatar for Pete Pete
October 10, 2019

Becoming a Security-Conscious Company (CHCon 2019) without notes

Avatar for Pete

Pete

October 10, 2019

More Decks by Pete

Other Decks in Technology

Transcript

  1. THE FOLLOWING TALK HAS BEEN WRITTEN FOR PEOPLE WHO WANT

    TO SEE SECURITY CULTURE TAKE ROOT AT THEIR COMPANY BY SOMEONE WHO’S LEARNING, EVERY DAY.
  2. Reasons to focus on security It’s a long-term competitive advantage.

    It’s practical risk mitigation. It’s the right thing to do, which speaks to your values as a company. ✓ ✓ ✓
  3. OKRs Appeals to engineering sensibilities. It works. Bonus: You only

    need to read the first three (-ish) chapters to get the gist. Good contender for the best 1½ hour you can spend for your company.
  4. Key Results 1. On 100% of our projects where we

    play a significant security role, a developer has passed a test for critical application security knowledge
 2. 100% of all employees (excluding those in their first month) have passed a test for basic workplace security
 3. 100% our client solutions pass the “critical” section of our internal security solution scoring matrix
  5. Key result #3 100% our client solutions pass the “critical”

    section of our internal security solution scoring matrix Measurable Measurable. NeEd to define this What counts as a “solution” anyway? NeEd to determine what’s “critical”
  6. Components with known vulnerabilities audited in CI Security role explicitly

    described in contract Passes ASVS Level 1 Etc… Client A Yes Yes Yes No Client B No No Yes No Client C Yes Yes Yes Yes Client D Yes No Yes No Passing 75% 50% 100% 25% 63% 9/16 =
  7. Top 10 OWASP Top 10s 1. Top 10 Most Critical

    Web Application Security Risks 2. API Security Top 10 3. Serverless Top 10 4. Cloud-Native Application Security Top 10 5. Top 10 IoT Vulnerabilities Don’t get lost in the weeds.
  8. A strong engineering culture Developers lift each other up Continuous

    improvement Gaps between teams are bridged Experimentation encouraged Wins and losses shared