Slide 1

Slide 1 text

[email protected] @okdt OWASP Life-time member 15+ OWASPer AppSec professional OWASP Japan

Slide 2

Slide 2 text

Congratulations!

Slide 3

Slide 3 text

The first era of OWASP Documents in Japanese thanks to Mr. Satoru Takahashi, 2004-2006

Slide 4

Slide 4 text

2012 OWASP Japan 1st meetup

Slide 5

Slide 5 text

Thank you for all your support!

Slide 6

Slide 6 text

SHIFT LEFT? By @akiko_pusu, 2017

Slide 7

Slide 7 text

Japanese

Slide 8

Slide 8 text

2021年 Developers Dislike Security: Ten Frustrations and Resolutions Chris Romeo, 2021. https://www.youtube.com/watch?v=nN7NH752onk

Slide 9

Slide 9 text

Shift-left analogy Let's do shift-left for progressive purposes. Front Loading Retrospective Kaizen Why 5 times

Slide 10

Slide 10 text

,FZGBDUPSTUPTVDDFFE4)*'5-&'5 MUTUAL UNDERSTANDING BUSINESS GOAL & RISKS KEEP UP TO DATE

Slide 11

Slide 11 text

WASFORUM.jp

Slide 12

Slide 12 text

No content

Slide 13

Slide 13 text

Hardening Project

Slide 14

Slide 14 text

No content

Slide 15

Slide 15 text

No content

Slide 16

Slide 16 text

Started

Slide 17

Slide 17 text

Spy comes…

Slide 18

Slide 18 text

Attackers

Slide 19

Slide 19 text

Attackers are very good at collaboration

Slide 20

Slide 20 text

Incident response

Slide 21

Slide 21 text

Marketplace

Slide 22

Slide 22 text

No content

Slide 23

Slide 23 text

SCORE BOARD

Slide 24

Slide 24 text

8-hour competition

Slide 25

Slide 25 text

No content

Slide 26

Slide 26 text

Softening Day

Slide 27

Slide 27 text

presentations

Slide 28

Slide 28 text

Hardening DX

Slide 29

Slide 29 text

“Kuromame 6”

Slide 30

Slide 30 text

No content

Slide 31

Slide 31 text

Summary: Key Success factors of SHIFT-LEFT MUTUAL UNDERSTANDING BUSINESS GOAL & RISKS KEEP UP TO DATE

Slide 32

Slide 32 text

My idea – “proactive controls” Be a guardrails. Discuss the most effective fixing points and timing Study their languages and environments Update frequently and show flexibility Give reasonable countermeasures, even if it is “plan-B” Teach how developers can check findings by themselves. Have the common goal and Praise their success Have good experience to collaborate with different roles. Join OWASP

Slide 33

Slide 33 text

#シフトレフト powered by OWASP For your photo! #shiftleft