Shift left, shift right, or run security right through the middle?

No ratings

Presented at GlobalAppSec-DC 2019 by

With software security blunders making headlines and businesses under increasing pressure to deliver software faster, development and security teams have been tasked to devise a strategy to satisfy demands for more secure software and more rapid application development. These combining forces have led to the emergence of DevSecOps, which represents a shift in IT culture to accommodate the growing need for both security and speed. However, security teams want to shift left, development teams want to shift right, and Ops team want testing throughout all phases of the development cycle—in other words, continuous testing. This leaves us with a lot of options and little guidance. What’s the best approach?This talk will examine how your organization can inject security testing at the right time, at the right depth, by using the right tools, by defining the right processes, and with the right people. In this way, you can achieve continuous testing rather than testing without a clear strategy in place.