Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris and Robert -- Security in the Methodology

28 min26 september 2016

Om avsnittet

How should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one. Waterfall makes phase gates, documentation, and specialized reviews visible, but often delays feedback. Agile breaks work into smaller increments, uses user stories and acceptance criteria, and creates opportunities to test security continuously. The hosts discuss stand-ups, sprints, continuous integration, threat modeling, abuse cases, reusable requirements, and the difficulty of defining “done” when security work spans multiple stories. Their conclusion is not that one methodology automatically produces secure software. Security succeeds when its activities fit the team’s real delivery process and provide useful feedback at the moment decisions are made.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Mentioned in this episode:
Agile Manifesto
Microsoft SDL

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Security in development methodologies
02:33 Why organizations still use Waterfall
04:07 Documentation and predictable phase gates
06:01 Where Waterfall came from
07:19 Applying security to each Waterfall phase
08:40 Moving from Waterfall to Agile
10:25 Testing inside every sprint
12:09 User stories and acceptance criteria
13:25 Stand-ups, retrospectives, and feedback
15:00 Continuous integration and Agile
16:49 What it means for a story to be done
18:19 Fitting AppSec into Agile work
20:32 Turning security needs into stories
21:50 Testing authorization requirements
24:25 Threat modeling and abuse cases
27:21 Final methodology lessons

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.