secure software @lady_nerd laura@safestack.io https://safestack.io - - PowerPoint PPT Presentation

secure software
SMART_READER_LITE
LIVE PREVIEW

secure software @lady_nerd laura@safestack.io https://safestack.io - - PowerPoint PPT Presentation

Architecting a culture of secure software @lady_nerd laura@safestack.io https://safestack.io In this talk Everything is not awesome The reality of our threat landscape and the need for change Security at speed Shifting mindsets and


slide-1
SLIDE 1

Architecting a culture of secure software

@lady_nerd laura@safestack.io https://safestack.io

slide-2
SLIDE 2
slide-3
SLIDE 3

In this talk

Everything is not awesome

The reality of our ‘threat landscape’ and the need for change

Security at speed

Shifting mindsets and adapting to our new environment

Architecting conscious security culture

Building a security-by-default culture

slide-4
SLIDE 4
slide-5
SLIDE 5

Everything is not awesome

slide-6
SLIDE 6
slide-7
SLIDE 7
slide-8
SLIDE 8

Sidenote

Shiny Pebbles are kind of interesting River rocks that shine under moonlight were often

  • volcanic. Volcanic rocks don’t get compromised

under high temperatures and shatter. “Shiny Pebbles” became a highly sought after cooking tool that would be passed between generations and had significant value both culturally and economically in Polynesian cultures.

slide-9
SLIDE 9
slide-10
SLIDE 10

Knights Warriors Armies Law Enforcement

Security Managers

slide-11
SLIDE 11
slide-12
SLIDE 12
slide-13
SLIDE 13

Hire more security people!

slide-14
SLIDE 14
slide-15
SLIDE 15

Everyone expects your security team to be a team….

Many hats not many people

slide-16
SLIDE 16
slide-17
SLIDE 17

Fear

Vulnerability

Shame Isolation Uncertainty

slide-18
SLIDE 18

4 million people 35 penetration testers 450 security professionals 1.2 per security team

P.S we are hiring

slide-19
SLIDE 19
slide-20
SLIDE 20

Security at speed

slide-21
SLIDE 21

continuous

slide-22
SLIDE 22

automated autonomous integrated repeatable scalable measurable respectful

slide-23
SLIDE 23

automated

“the best technical people I know work

really hard to make themselves redundant”

slide-24
SLIDE 24

Deployment Provisioning Testing Static analysis Vulnerability mgmt

slide-25
SLIDE 25

autonomous

“no bottlenecks, breakdowns or ripples”

slide-26
SLIDE 26
slide-27
SLIDE 27

Skills Authority Accountability every team

slide-28
SLIDE 28

integrated

“bite-sized security that works with every step

  • f your lifecycle”
slide-29
SLIDE 29

Dependency checkers Static analysis and code review

Integrate security into your pipeline

Vulnerability scanners Threat assessment tools Requirements generators

slide-30
SLIDE 30

Woven in to keep you going Respected enough to stop you

slide-31
SLIDE 31

repeatable

“security fails when it’s a special event”

slide-32
SLIDE 32

scalable

more than just a single team experiment

slide-33
SLIDE 33

measurable

if you can’t measure it, how do you know you made things better?

slide-34
SLIDE 34

respectful

every action has a cost, value the time and resource needed to complete an action

slide-35
SLIDE 35

Architecting conscious security culture

slide-36
SLIDE 36
slide-37
SLIDE 37

hire good people

“learn what good means for your organisation”

slide-38
SLIDE 38

keep good people

money isn’t normally the only factor

slide-39
SLIDE 39

skills, authority, accountability increase effectiveness in role

Agency Incentivization Acknowledgement

increase loyalty to role

slide-40
SLIDE 40

blameless (fearless)

extend blameless culture to security

slide-41
SLIDE 41

Use understanding attack and risk as problem solving, creative, lateral thinking

You shouldn’t feel naughty You shouldn’t feel sad

slide-42
SLIDE 42

data driven security

take out the emotion, measure and respond

slide-43
SLIDE 43

Patch adoption Upgrade rates User profiles (technology and usage) Device patterns Browser patterns Chronological and location patterns Error rates Query times Query data set size and complexity

slide-44
SLIDE 44

language matters

consistent, concise, inclusive

slide-45
SLIDE 45

sustainability and stamina

save crisis responses and stress for special

  • ccasions
slide-46
SLIDE 46

TL;DR

Everything is not awesome

The reality of our ‘threat landscape’ and the need for change

Security at speed

Shifting mindsets and adapting to our new environment

Architecting conscious security culture

Building a security-by-default culture

slide-47
SLIDE 47
slide-48
SLIDE 48

@lady_nerd laura@safestack.io https://safestack.io