Dev, Sec, Oops: How Agile Development increases Threat Landscape
12:45 - 13:25, 24th of September (Thursday) 2020/ SECURITY STAGE
If you ask a product security engineer, what is the main entry point for an organization’s adversary to gain access to their crown jewels, he would answer: “A human.” He most likely means those employees with a low level of security awareness. In today's reality, security engineers are the guards of employees’ security-related code of conduct. But who guards the guards?
Based on real scenarios of supply chain attacks, we’ve performed for various software developing companies, we will demonstrate the weakest points of the “Agile Security” paradigm in software development lifecycle and redefine Code of Conduct for product development.