You’re not testing
Gather
Requirements
Build & Test
Certify
Deploy
Warranty
& Support
Public Domain Photo provided by Peterrhyslewis via Wikimedia Commons
Security “Testing”
Slide 5
Slide 5 text
Do Assurance not Control
Gather
Requirements
Build & Test
Certify
Deploy
Warranty
& Support
Public Domain Photo provided by Peterrhyslewis via Wikimedia Commons
Quality Control
Slide 6
Slide 6 text
Security is an Assurance Activity
Gather
Requirements
Build & Test
Certify
Deploy
Warranty
& Support
Public Domain Photo provided by Peterrhyslewis via Wikimedia Commons
Security Testing
Security Testing
Security Testing
We are Agile!
Signs you’re actually “Fauxgile”:
• Zero product documentation
• Lots of project documentation
• Teams bigger than about 9 people
• Testing is only done by “QA”
• Lack of key Agile metrics
Slide 9
Slide 9 text
You are not special
Public Domain Photo produced by USDA