Scratching the Surface of your CD? - Ofer Maor - AppSecUSA 2018
272 views · Published 19 November 2018 · 36:25 · Indexed 26 September 2026
Channel: OWASP Foundation · 2018 · Science & Technology
Continuous Delivery (CD) introduces a new set of challenges for application security testing, even compared with already fast Continuous Integration (CI) and DevOps methodologies. CD development organization can produce hundreds or even thousands of software updates per day, some of them taking no longer than a few hours from beginning to end. This puts pressure even on the best fast AppSec testing methodologies, such as fast incremental testing, restricted testing, etc. True continuous testing calls for true, inline, continuous security testing, which does not rely on any dedicated testing slots. In this talk we will talk about some of these concepts - how to streamline security testing in the background, how to fit it into modern A/B testing cycles, and how to build an approval process that fits a modern CD workflow, rather than an old security go/no-go approach. Join this talk if you would like to turn your application security testing methodology into one that can fit whatever development velocity your organization wants to go at! Speaker Ofer Maor Director, Solutions Management, Synopsys - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
35:56
HTML5 JS Security - maty siman
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
40:10
Tin Zaw Scott Matsumoto - Threat Modeling A Brief History and the Unified Approach at Intuit
-
2:26:27
OWASP AppSecUSA 2014 - Breakers Track - Friday
-
53:26
OWASP AppSecUSA 2014 - Keynote: OWASP Global Board
-
49:40
Building Your Application Security Data Hub: The Imperative for Structured Vulnerability Information
-
48:32
Blended Web and Database Attacks on Real-time, In-Memory Platforms - OWASP AppSecUSA 2014
-
45:23
OWASP A9: A Year Later - Are you still using components with known vulnerabilities? - AppSecUSA 2014