DevSecOps - Securing a great DX

By Stefan Streichsbier

Elevator Pitch

In the software engineering world, change is the only constant. In the last decades, the frequency of that change has exploded. However, Security seems to be at odds with these changes and is trying to stay relevant. Are you a developer that wants to write secure code? Then this talk is for you!

Description

In the software engineering world, change is the only constant. And in the course of the last decades, the frequency of that change has exploded. What Agile has brought to software teams, DevOps is now bringing to the entire organization. And the results speak for themselves. The DevOps high-performers are killing it. Insane deploy frequencies of features, high reliability of applications, and high productivity of cross-functional teams have amplified the speed at which ideas become a reality.

In parallel, Application Security was doing its own thing and to a large part remained oblivious to all the impressive improvements that were happening in software engineering. Because breaking an application doesn’t need any knowledge of how it was created in the first place.

This talk will cover anti-patterns that are preventing application security from being adopted by development teams, such as:

  • Signals versus Noise
  • Lost in Translation
  • Bad Developer Experience (DX)