Integrating security into modern software development : a workflow study / Lucas Charles.
- Format:
-
- Author/Creator:
-
- Contributor:
-
- Conference Name:
-
- Language:
- English
- Subjects (All):
-
- Physical Description:
- 1 online resource (1 streaming video file (30 min., 41 sec.)) : digital, sound, color
- Place of Publication:
- [Place of publication not identified] : O'Reilly Media, [2019]
- Summary:
- "Traditional application security testing has been targeted to security professionals and is regarded as a separate process from development. This separation and delay creates friction in the process, with many trade-offs required. In an effort to improve application security testing, the new chant has been "shift left" to remove more vulnerabilities earlier and empower the developers. Lucas Charles (GitLab) examines the shortcomings of most shift-left efforts and how cloud native environments, Agile DevOps processes, and minimum viable products with rapid iteration wreaks havoc on traditional security methodologies. He dives into how to bring security into DevOps while avoiding a complex DevOps toolchain that must be integrated with security testing and explores new ways of thinking of app security to turn the industry on its head by using concurrent DevOps, a method that makes it possible for product, development, QA, security, and operations teams to work at the same time. You'll learn the three key requirements of your application security process needed to get you onto the road of an efficient and secure software development lifecycle (SDLC)."--Resource description page.
- Participant:
- Presenter, Lucas Charles.
- Notes:
- Title from title screen (viewed March 9, 2020).
- OCLC:
- 1144107454
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.