Developer Security Based on 15 Years Experience

The Big Fix 2023 by Snyk

2023/02/28

AI Generated Summary

This talk shares insights from 15 years of experience working with developers and security, focusing on bridging the gap between these two communities and making security more accessible to developers.

Key Topics Discussed

The Problem:

Data Breach Reality (2011-2021):

The Solution - DevSecOps Approach:

Developer Perspective - The Core Message:

How to Commoditize Security:

Veteran Infosec Professionals’ Advice to Developers:

Key Points:

Important Insights:

Actionable Takeaways:

  1. Developers: You are responsible for security of your apps
  2. Security professionals: Listen to developer needs, address them from security point of view
  3. Trust developers: They are highly intelligent - trust them to do good once you provide information
  4. Commoditize security: Make it automatable, documentable, testable, repeatable
  5. Pick tools that work for you: Automate security stuff
  6. Don’t let security on your stuff: Don’t rely on security team for everything
  7. Focus on collaboration: Not blame game
  8. Build allies: In the environment
  9. Common goals: For greater good
  10. Encourage security mindset: Especially outside security team

Important Projects Mentioned:

Personal Background: