Defining a Secure SDLC

Episode 17 January 19, 2023
YouTube video

A secure software-building pipeline is more than just the sum of its security tools. How an organization manages their tooling can mean the difference between AppSec chaos and AppSec success. Appropriate configuration, gaining visibility needed to make sense of tool outputs, collecting those outputs with the right frequency, and deciding when/where those tools are deployed stage-wise in the assembly line are all key process-oriented exercises. And like with any exercise, technique and consistency are everything!