AppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan Brätsch @OWASPGLOBAL
AppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan Brätsch  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
Are you an AppSec professional struggling to align security with your company's project management (PM) processes? Whether you're a software developer, architect, or CISO, this talk will show you how to turn PM frameworks into powerful tools for building secure applications.


We'll explore how common PM methodologies like Agile and Waterfall impact security requirements and compliance.

We'll discuss the challenges of aligning national security compliance systems with company-specific requirements and various PM implementations.

You'll learn how to:

Understand how security requirements work within different PM frameworks
Choose the right PM framework for your organization's security needs
Effectively introduce and implement AppSec requirements into your company's PM framework
Understand how large companies approach PM frameworks and security requirements, enabling you to work with them more effectively

This talk is ideal for those who:

Work in a large company and want to better understand and influence how security is handled within the existing PM framework
Work in a small company and want to tailor a PM framework to optimize AppSec
Work with external clients (large or small) and need to understand their PM-driven security perspectives
By the end of this session, you'll have a deeper understanding of how AppSec and PM intersect. You'll be equipped with strategies to integrate security into your projects, regardless of the PM framework used, leading to more secure software and smoother collaborations.


-

Managed by the OWASP® Foundation
owasp.org
AppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan BrätschOWASP Coraza - Web Application Firewall - Juan Pablo TossoBenchmarking Scanner Blind Spots: How Runtime Context Uncovers Hidden VulnsYour RPA is Mine: Complete Takeover of RPA EcosystemsNoise vs. Signal: The Central Paradox of LLMs in Threat Modeling track 2BREAKStriding Your Way to LINDDUN: Threat Modeling for Privacy - Shanni Prutchi, Chris BushOWASP DefectDojo - Matt TesauroOWASP DefectDojoOWASP Global Board of Directors Meeting - May 2025Developer-Centric Threat Modeling: Embedding Security in Agile WorkflowsEscaping Vulnerability Hell: Bridging the Gap Between Developers and Security Teams - Ahmad Sadeddin
OWASP Foundation |

AppSec Meets Project Management: Hacking the Frameworks for Secure Software - Stefan Brätsch

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER