Upgrade to Pro — share decks privately, control downloads, hide ads and more …

«Dev, Sec, Oops: How Agile Security increases A...

«Dev, Sec, Oops: How Agile Security increases Attack Surface», Денис Макрушин

Avatar for OWASP Moscow

OWASP Moscow

March 05, 2020
Tweet

More Decks by OWASP Moscow

Other Decks in Programming

Transcript

  1. DEV, SEC, OOPS: HOW AGILE SECURITY INCRESES ATTACK SURFACE Denis

    Makrushin Head of Advanced Security Research, Huawei https://twitter.com/difezza
  2. Agile Security: key principles • Don’t reinvent it • Do

    it incrementally • Automate it • Process (CI/CD) • People (DevSecOps) • Tools
  3. How to fix it • Secure SDLC • Educate your

    User • OSINT your product If you are Security Vendor: If you are Security Engineer: • Know your Attack Surface • Do not click on links • Follow your Code of Conduct • Scan your Open Source