Presented at AppSec USA 2013
Nov. 21, 2013, 9 a.m.
Video of session:
Software development is moving much faster than application security with new platforms, languages, frameworks, paradigms, and methodologies like Agile and Devops.
Although we're making progress in application security, the gains are much slower than the stunning advances in software development. After 10 years of getting further behind every day, software *assurance* is now largely incompatible with modern software *development*. It's not just security tools - application security processes are largely incompatible as well. And the result is that security has very little influence on the software trajectory at all.
Unless the application security community figures out how to be a relevant part of software development, we will continue to lag behind and effect minimal change. In this talk, I will explore a radically different approach based on instrumenting an entire IT organization with passive sensors to collect realtime data that can be used to identify vulnerabilities, enhance security architecture, and (most importantly) enable application security to generate value. The goal is unprecedented real-time visibility into application security across an organization's entire application portfolio, allowingall the stakeholders in security to collaborate and finally become proactive.
- Co-founder and CTO - Contrast Security
I've been in security since the late 1980's and have been blessed with the opportunity to help start three great organizations: Aspect Security (recently sold to EY), OWASP, and Contrast Security.
I'm coming to AppSec EU to meet *you*. I'm easy to find :-) and love to talk about basketball, boomerang design, DevSecOps, security instrumentation, replacing SAST/DAST/WAF with IAST/RASP/SCA, cost-effective appsec programs, OWASP history, and Dad-life (four kids, two in college). I am convinced that appsec as we know it must change and that DevSecOps is the path forward. I'd love your help!