DevOps Application Security Teams for the Rest of Us

No ratings

Presented at BSidesNashville 2019 by

Is it possible to do AppSec really well in a distributed DevOps environment at scale? Without hesitation, many in the security industry would answer with an emphatic "No!" Picture an organization with hundreds of projects in simultaneous flight, deploying continuously at any given time. Perhaps this is your organization? How can security be meaningfully injected into such apparent chaos?Well, actually, it can be done. There are solutions that work and work well. In fact, you might even find that application security can be more robust than when you thought you had a handle on it – you know, back in the “good” ol' days of waterfall. One of the keys to making this work is a highly skilled, embedded AppSec team. Building and maintaining such a team, however, may appear prohibitively expensive and unmanageable. It need not be so.This presentation will show you how to implement an AppSec program and develop an AppSec team that will fit well and function effectively within a large-scale distributed DevOps shop – without draining your budget! We will take you through our own journey of discovering what actually works (and what most certainly does not) within these challenging development environments, while providing specific details on the following: selling the program to upper management, building support throughout the organization, recruiting the AppSec team, training the AppSec team, interacting with the CISO's organization, impacting the product development culture and gaining influence, maintaining momentum, closing the gaps.Doing AppSec properly in a distributed DevOps world won't be easy – nothing in life that's worthwhile ever is – but it is realistically achievable. If you are struggling with AppSec, this talk will give you hope for the future and a realistic plan for embedding security into your products more successfully than ever before.