App-abet Soup: Should You DAST, SAST, IAST or RASP?

No ratings

Presented at InfoSecurityEurope 2019 by

While web applications offer convenience to businesses and customers alike, their ubiquity makes them a popular attack target for cybercriminals. As a result, web application security testing, or scanning and testing web applications for risk, is essential - so is protecting them. But with vendors using their own marketing buzzwords and spinning their technology, buyers are dazed and confused. My goal is to clear up some of this mess by explaining the relationship of DAST/SAST, what the "I" in IAST is, and how RASP fits into the equation.Learning Outcomes:Navigate the world of application security testing and run-time protection toolsUnderstand the critical factors in choosing a solution that's right for your organisationCut through the noise of vendor-defined terms and market speakDetermine the critical capabilities required for your business needsHow a solution should integrate into your overall security program to ensure scalability, flexibility, and efficiency