Home Research Dev Sec Oops: how agile security increases attack surface

Dev Sec Oops: how agile security increases attack surface

by Denis Makrushin
651 views

If you ask a product security engineer, what is the main entry point for an organization’s adversary to gain access to their crown jewels, he would answer: “a human.” He most likely means those employees with a low level of security awareness. In today’s reality, security engineers are the guards of employees’ security-related code of conduct. But who guards the guards?

Based on real scenarios of supply chain attacks, we’ve performed for various software developing companies, we demonstrated the weakest points of the “Agile Security” paradigm in software development lifecycle and redefine Code of Conduct for product security.

The research is presented at OWASP Israel.

Leave a Comment

You may also like