Black Hat USA 2018 - SDL That Wont Break the Bank @HackersOnBoard
Black Hat USA 2018 - SDL That Wont Break the Bank  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Over the last fifteen years, many large software development organizations have adopted Security Development Lifecycle (SDL) processes as effective approaches to delivering secure software. Motivation for SDL comes from the realization that software vulnerabilities can have real impacts – on information security, on organizations' reputations, on customer satisfaction, and on revenues. But what if you don’t have 40,000 developers and run a small to medium dev shop?

Fortunately, SDL adoption need not be "only for the rich." While large organizations have the resources to create large teams and customized tools, smaller organizations have the advantage that they can focus an SDL on the specific products, tools, and threats that are relevant to the software they produce. They can also benefit from a wide array of free and affordable resources that can help them address many of the challenges posed by creating and sustaining an SDL program. With management commitment to SDL fundamentals and an investment of resources proportional to the size of the development organization and its products, it's possible for small organizations to build an SDL program and deliver software that customers will find secure.

This briefing will describe some resources that can help smaller organizations create an effective SDL program. It will also outline some secure development concerns that may be especially important to those organizations – such as dependence on software they didn’t write – and ways that they can address those concerns.
Black Hat USA 2018 - SDL That Wont Break the BankDay Zero A Road Map to #BHUSA 2018Black Hat USA 2018 - The Air Gap JumpersBlack Hat USA 2018 - AI & ML in Cyber Security - Why Algorithms are DangerousBlack Hat USA 2018 - Stealth Mango and the Prevalence of Mobile SurveillancewareBlack Hat USA 2018 - No Royal Road … Notes on Dangerous GameBlack Hat USA 2018 - Deep Neural Networks for Hackers Methods, Applications, and Open Source ToolsKeynote Optimistic Dissatisfaction with the Status QuoBlack Hat USA 2018 - New Norms and Policies in Cyber-DiplomacyDEF CON 27 - Daniel Romero - Why You Should Fear Your mundane Office EquipmentProtecting the Protector, Hardening Machine Learning Defenses Against Adversarial AttacksDEF CON 27 - Infiltrating Corporate Intranet Like NSA _Pre-auth RCE on Leading SSL VPNs
HackersOnBoard |

Black Hat USA 2018 - SDL That Won't Break the Bank

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER