Author: OWASP Foundation - Bewertung: 0x - Views:1
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing it. Too often, the shift-left mantra consists of implementing AI code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-Powered Security Fixes.
Should security architecture, security requirement analysis, penetration testing, and threat modeling be conducted by security professionals, or is the answer to automate everything? Don’t automate yourself away from thinking! Design must start before coding, and being agile means that the whole team needs to participate. This is not work done by security champions, but by everyone on the development team, not only the selected few, but an army of appsec volunteers. But how?
The answer is gamification.
Most people will agree that AppSec is essential; they just forget what you were saying once they leave the room. The brain is amazing. It can let you learn to ride a bike, write poetry, learn a new programming language, or even fall in love, but if your brain is so amazing, why do your colleagues forget everything you said about application security during your last meeting?
This session will discuss how you can utilize games to scale your application security program, foster agency, empathy, community, spark imagination, and stimulate the brain. When choosing a strategy for making your applications more secure, don’t choose reading materials, presentations with “talking heads,” or meetings as a medium for increasing awareness and knowledge about application security. Instead, focus on activities that can be repeated regularly that are both relevant and engaging to the work you are doing. When employees are authentically involved and curious about their learning, their heightened focus and emotional connection lead to better memory formation and the application of knowledge. Numerous studies report that emotions have a significant impact on human cognitive processes. This underpins the reasoning behind why games can enhance learning over time, which is why having an extensive collection of games in your arsenal is beneficial when teaching others about application security.
Johan Sydseter
Admincontrol AS
Application Security Engineer
Norway
cornucopia.owasp.org
https://www.linkedin.com/in/sydseter
Johan Sydseter is one of the co-leaders of OWASP Cornucopia and the co-creator of the OWASP Cornucopia Mobile App Edition. he is a living AppSec Pokémon, application security engineer, developer, architect and DevOps practitioner. He has 17 years of experience building and designing backend and frontend solutions. He is also a regular contributor to Cornucopia. He has held several presentations on application security at various international conferences in the past and currently works as an application security engineer at Admincontrol AS a Euronext subsidiary.
-
Managed by the OWASP® Foundation
https://owasp.org/