Onboard security in software companies 软件企业的安全之道 Wenjun Wang(王文君) Hewlett Packard Enterprise software security lead Self introduction –Hewlett Packard Enterprise software security lead, responsible for BU security with $1B revenue –10+ years enterprise software then security –CSSLP & CISSP –Co-author Web应用安全威胁与防治 Vulnerabilities 以上内容来自于乌云网 Adhoc solution What should do The fact Cost to fix these issues RnD’s voice to security Revenue driven Legacy I’m a developer Security scanner RnD’s impression to security guys RnD’s expectation to security guys Security guys’ challenge Product team Security architect Security as a quick start 1. Create security bug type Damage Security bug • Severity • Impact • Released version Verify success • Meet release criteria • Mitigation is provided Reproducibility Exploitability Affected users Discoverability 2. Security user story User story • Agile • Attacker view Verify success • In backlog • Test cases “As an [operator], I want to [do something] so that I can [derive a benefit]” “As an [attacker], I want to [do something] so that I can [damage the system]” 3. Security dashboard Dashboard • Aggregation • Drill down Verify success • Stakeholders are aware • Business decision So evolve On board security program Low hanging fruit Adhoc solution Security awareness training Diversity Options • Management • Dev • QA • Instructor based • Web based • Event Security release criteria Risk Criteria • DREAD • CVSS3 • Threshold • Business balance Threat modeling and security design review Threat Review • Threat list • Refresh list • Security pattern • Security user story Security assessment Automatic Manually • Static • Dynamic • Check list • Pen test Risk response Pre-event Post-event • 3rd party lib scan • Subscription • Action plan • Risk tracker Apply what you learnt today 3 months 3 weeks 3 days • Know security methodology in this document • Handle low hanging fruit in your company • Start onboarding security program

pdf文档 2016-《软件企业的安全之道》

安全研究库 > 网络论坛材料 > 20160Con(公开版)-24号 > 文档预览
22 页 0 下载 39 浏览 0 评论 0 收藏 3.0分
温馨提示:如果当前文档出现乱码或未能正常浏览,请先下载原文档进行浏览。
2016-《软件企业的安全之道》 第 1 页 2016-《软件企业的安全之道》 第 2 页 2016-《软件企业的安全之道》 第 3 页 2016-《软件企业的安全之道》 第 4 页 2016-《软件企业的安全之道》 第 5 页
下载文档到电脑,方便使用
还有 17 页可预览,继续阅读
本文档由 张玉竹2022-04-08 09:04:36上传分享
给文档打分
您好可以输入 255 个字符
安信天行文库的中文名是什么?( 答案:安信天行 )
评论列表
  • 暂时还没有评论,期待您的金玉良言