Apply security at all layers. • Automate security best practice. • Protect data in transit and a rest. • Keep people away from data. • Prepare for security events. AWS - Security https://wa.aws.amazon.com/wat.pillar.security.en.html
developers showed interest in security topics. 14.6% of them does not show interest in security topics. This group is mostly composed of Backend Engineers. www.ingenieriadelcaos.com
not practice OWASP during the software development. In this group there are 7 Software Architects and 73% are Backend Engineers. 51 engineers apply best secure development practices. www.ingenieriadelcaos.com
do not have security steps enabled in pipelines. This group includes 5 Software Architects, 14 Backend Engineers and only 1 Frontend Engineer. 100 people have security integrated in the CI/CD process. www.ingenieriadelcaos.com
which imposes us a challenge: motivation and culture. Conclusion www.ingenieriadelcaos.com Group of people is mostly conformed by Backend Engineers. We needed motivation strategies!
how drastically important secure SDLC is for businesses, customers, and society at large. www.ingenieriadelcaos.com https://techwireasia.com/2021/02/are-self-taught-coders-a-cybersecurity-problem/
failures through proactive experimentation to build confidence in the system’s ability to defend against malicious conditions in production. Security Chaos Engineering Book www.ingenieriadelcaos.com
a chance to put their skills to the test in a real-world, gamified, risk-free environment. A Chaos GameDay is a practice event, and although it can take a whole day, it usually requires only a few hours. The goal of a GameDay is to practice how you, your team, and your supporting systems deal with real-world turbulent conditions.
Drop a folder like a script would do in production. • Software secret clear text disclosure. • Permission collision in a shared IAM role policy. • Disable service event logging. • API gateway shutdown. • Unencrypted S3 Bucket. • Disable MFA.
from the requirements gathering and architectures design. Impact in Development Teams Continuous testing team were able to generate tests to confirm security of data. An opportunity to involve to business for example by asking them if it was possible to block multiple login for users. We highlighted the importance of secure dependencies at the time of software design and implementation.
clear data in logs. Make all software activities auditable. Perform a vulnerability scan of the software. Use session management for frontends. Do not use cookies and browser storage. Use MFA for critical application actions. Use of short-lived effective links for documents to be delivered.
scan. Use hashing for validation of software elements. Use security blocking when users have unsuccessful attempts. Generate container images in a secure way. Use of containers, with the minimum privilege Separate environments from applications. Separate databases from applications.