Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Apollo Clark -- Malicious User Stories

23 min22 maj 2018

Om avsnittet

How do you turn a security requirement into something a development team can build and test? Apollo Clark explains malicious user stories: short descriptions of what a particular attacker should not be able to accomplish. Speaking at the Source Conference in Boston, he connects these stories to business goals, regulatory requirements, and automated tests in a delivery pipeline. Apollo then steps back to define DevOps through values, feedback, and continuous learning rather than a shopping list of tools. The discussion follows those ideas into practical automation with Gauntlt, reusable security checks, containers, and infrastructure deployment. He shares lessons from working with executives and engineers, arguing that security succeeds when teams agree on outcomes and translate them into repeatable technical practices.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Apollo Clark:
Apollo Clark on GitHub

Mentioned in this episode:
Gauntlt
The DevOps Handbook
Terraform

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Malicious user stories with Apollo Clark
01:41 Apollo’s security origin story
03:14 From user personas to malicious user stories
05:12 Writing testable attacker-focused outcomes
05:50 Translating regulations into security stories
07:22 Integrating the stories into DevOps
08:37 Defining DevOps through values and the three ways
11:59 Putting security into automated delivery
13:00 OWASP contributions and Gauntlt
15:35 Running security checks with containers
19:10 Gauntlt’s direction and practical limitations
19:39 Automating infrastructure deployment
20:38 Start with what your organization values

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.