AppSec Automation: Five Steps to Achieving Developer-First Security

Logo
Presented by

Steven Zimmerman, Synopsys

About this talk

Securing software takes teamwork—a unified approach from development through testing and into production. But each team has a distinct set of requirements and workflows that need to align to realize a concerted push for security. And while developers influence risk posture, they are often not trained in or focused on software security practices. How can you make the effort that developers and DevOps teams are already putting in more valuable to the business? What's the best way to cultivate highly security-conscious developers so your software becomes more secure over time? Is there a way to derive tangible benefits for the business, the team, and the individual? Join us as we break down a five-step process with real-world applicability. Topics include • The critical distinction between developers' security awareness and their security capability • Mechanisms to automate risk detection and accelerate remediation across the pipeline, including at the developer desktop • How to establish security gates in DevOps pipelines in a way that doesn't derail development or lead to missed shipping deadlines • How to create a DevSecOps initiative that can evolve with the business and enable developers to sustain security requirements as part of their day-to-day • Ways to maximize security's value to the business and its customers
Related topics:

More from this channel

Upcoming talks (14)
On-demand talks (110)
Subscribers (60619)
Synopsys Software Integrity Group provides integrated solutions that transform the way development teams build and deliver software, accelerating innovation while addressing business risk. Our industry-leading portfolio of software security products and services is the most comprehensive in the world and interoperates with third-party and open source tools, allowing organizations to leverage existing investments to build the security program that’s best for them. Only Synopsys offers everything you need to build trust in your software.