SecDevOps: Current Research and Best Practices

No ratings

Presented at owaspapseccalifornia 2018 by

Abstract:The last decade has seen widespread changes in how organization develop and release software. It's not uncommon now for companies to dynamically provision huge numbers of servers using cloud providers based on need, automatically configure the servers with change management systems like Puppet or Chef, and push new code into production tens to hundreds of time per day. In most companies, developers outnumber security engineers by 50:1 or more. How do you keep up?