Testing with your left foot forward

No ratings

Presented at GlobalAppSec-DC 2019 by

DevOps has brought many benefits to security - SAST and SCA security tools have been baked into build pipelines. To some extent, even automated DAST has been integrated into our build pipelines. However, this leaves a gap with manual testing. Manual assessments occur, be it in house or via bug bounties, and at best we can automate the delivery of our results into a defect tracker like Jira. However, this just adds to the backlog - we can do better. This talk will explore how manual testing efforts can - using standard, pre-existing dev & QA tools - be more tightly coupled into the build pipeline and drive faster remediation.