Shift Level with CISO’s

Snyk Panel Discussion

2021/08/31

AI Generated Summary

This is a Snyk panel discussion on “Shift Left Strategy with CISOs” featuring Anant Shrivastava (Technical Director, NotSoSecure) and Patrick Pachapa (Director of Information Security and Risk, Altia Group), moderated by Vandana.

Panelists

Key Topics Discussed

DevOps and Security Teams Working Together:

Larger vs Smaller Organizations:

Handling Relationships:

De-risk Individuals, Focus on Collective Responsibility:

Two Angles:

Security People Getting Into Organization:

In-House vs Vendors:

Skeleton Team:

Shift Left:

Sony Television Example:

Security Operations:

Key Insights:

Actionable Takeaways:

  1. DevOps and security teams still in silos - lot of work to do
  2. CISO as scapegoat - Equifax example, CISO fired
  3. De-risk individuals, focus on collective responsibility
  4. Respect experience of people already in organization
  5. In-house vs vendors - need skeleton team (3-5 people) who understands
  6. Shift left unavoidable - releases every week/day
  7. Tools must be customized for large environments
  8. Sony television example - automation eliminates defects
  9. Security operations - how offload or handle in-house
  10. Three musketeers: Development, testing, security - all working together