DiscoverOWASPAre we making our engineers blue? TASH NORRIS
Are we making our engineers blue?  TASH NORRIS

Are we making our engineers blue? TASH NORRIS

Update: 2019-07-05
Share

Description

OWASP Global AppSec Tel Aviv
https://telaviv.appsecglobal.org/

Our engineers are going from software engineers to software + infrastructure + network + database engineers, and they’re delivering faster. In an environment of continuous deployment how can we ensure that as security teams we’re scaling as fast as our applications are?

In this talk we’re going to be covering how we turn our engineers blue. Not sad; not by telling them to fix every possible threat vector before building any new features and not by saying no. We’re going to start turning them into our extended blue team, giving them tools, techniques and processes to better secure our estate.

We’re going to be covering off a few different TTP’s for our engineers using real threat models as examples;
How to use incidents to evolve our threat models
Using incidents to better evolve our understanding of the threat landscape
Determining other attack vectors that could contribute to the same outcome as the incident (with threat example)
How to create incremental threat models/ rapid threat models
Why and how we should write and use security tests to validate our models
How to use BDD tests (and contribute to the Cloud security OWASP project)
Why we should write tests for threat vectors we have proven mitigations for (with threat example)
How to use tests to educate product owners/ project managers on threat vectors
The power of POC’ing attack vectors from our models to evolve them further.
Example: Cloudfront subdomain hijacking
Using POC's to discover new threat vectors and provide security awareness training for engineers
How we build, evolve, share and ultimately transfer ownership of these models to our engineering teams - teaching them to be our blue team.
How to create security champions (building programs, what programs should include)
How to integrate rapid threat modeling into the SDLC

Tash Norris
AppSec Lead, Photobox Group
Senior Cloud Security Engineer at Photobox Group. Currently building tools and processes to automate all the things/ make the Cloud more secure.

-

Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Are we making our engineers blue?  TASH NORRIS

Are we making our engineers blue? TASH NORRIS

OWASP