KEYNOTE: Security as a Product

No ratings

Presented at BSidesKnoxville 2018 by

Enterprise security teams too often are relegated to performing as firefighting, headless chickens – which is a waste of time, energy, passion, and talent. Rarely do we see the sort of strategic thinking, overarching vision, and fostering of organization-wide consensus that is required to proceed on projects in other parts of the business. At best, security teams will have a project manager to help individual projects stay on track, but this can lead to valuable streams of work on a micro-level that fail to accomplish meaningful change on a macro-level. At worst, security teams face burnout and frequent turnover due to continued disappointment over lack of progress in the security program.Instead, I believe security should be treated as a product, which includes:Defining an extended strategy to address ongoing needsUnderstanding what the needs are across various stakeholdersCreating and prioritizing requirements, and maintaining a roadmap of featuresManage the release of featuresServing as the “face” of the product to the rest of the organization to cultivate consensus, answer questions, and solicit feedbackI’ll give specific examples of how this framework can help improve the performance (and even the oft-overlooked morale) of security teams and create the scaffolding necessary to build and scale security programs that engender meaningful progress.