A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Search Irongeek.com:

Affiliates:
ISDPodcast Button
RootSecure Button
Social-engineer-training Button
Irongeek Button

Web Hosting:
Dreamhost Logo
Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


Lessons Learned Implementing SDLC – and How To Do It Better -Sarah Clarke Notacon 11 (Hacking Illustrated Series InfoSec Tutorial Videos)

Lessons Learned Implementing SDLC – and How To Do It Better
Sarah Clarke
Notacon 11

Synopsis
Developers and Quality Engineers are wonderful people who understand how to create, test, and validate features. They frequently aren’t, however, educated in school on architecting applications to prevent security failures, coding to not introduce security bugs, and testing to validate secure functionality.
The language of development – features, releases, agile – is not the same as security – XSS, CSRF, managing session state.
We have to communicate better with our developers and QEs, to inspire them to care, in their language; we have to work with senior management to identify how security fits into their needs to get buy-in and support.
This is a discussion on how that communication works best; overcoming cultural sticking points, and iterating through creating a process that creates better code without slowing down business.

Bio
Sarah Clarke is a Senior Security Engineer at Genesys Telecommunications. years of experience in IT, seven of which have specialized in Security. She has worked with nonprofit, government contracting, ISP, financial sector, and telecommunications organizations; currently, she is enjoying serving as application security testing and vulnerability management SME for Genesys Cloud, a global SaaS IVR and virtual call center PCI (and etc) compliant service provider.
Sarah’s passion for application security began with the Toyota break failure bug and continued with the work by Barnaby Jack and Jay Radcliffe on poor software design causing fatal error conditions in pacemakers and insulin pumps. She chooses to focus on helping teams make better software, to protect the innocent, save lives and identities.
Sarah is a member of Infraguard, holds four industry certifications, recently presented at Shmoocon Firetalks 2014, and volunteers to support the security community whenever possible.

Coming Soon

Back to Notacon 11 video list

Printable version of this article

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2014, IronGeek
Louisville / Kentuckiana Information Security Enthusiast