Software security is hard and is becoming increasingly elusive as applications increase in complexity and the attacks against them become more sophisticated. To suitably secure their applications, organisations must formalise their application security efforts, specifically in the Software Development Life Cycle (SDLC). ThinkSmart will facilitate an interactive workshop on how you can bootstrap information security into your SDLC. It will cover some of the popular development methodologies and discuss how security should be woven into them. Included will be a discussion and demonstration of useful application security frameworks and techniques from resources such as OWASP. If you want your development team to learn and share on how to implement a secure SDL then this workshop is for you. Key discussion points: • Security and popular development methodologies Paul van Woudenberg • Demonstration of useful application security frameworks • Techniques from resources such as OWASP • Implementation of a Secure SDL