WeAreDevelopers LIVE • Feb 1, 2022

Maturity assessment for technicians or how I learned to love OWASP SAMM

Mathias Tausig

Are you still waiting for late-stage penetration tests to catch critical vulnerabilities? Discover how OWASP SAMM empowers developers to shift security left directly into the IDE.

Pause
Mute Enter Fullscreen
#1 about 6 min

Introduction to secure development and OWASP SAMM

Why focusing purely on secure coding is insufficient without a comprehensive secure development lifecycle.

#2 about 5 min

Common consequences of secure development lifecycle failures

How undefined responsibilities and missing threat models lead to expensive production vulnerabilities.

#3 about 6 min

Exploring the structure of the OWASP SAMM framework

The core business functions, security practices, streams, and maturity levels that make up SAMM.

#4 about 4 min

Mapping production vulnerabilities to OWASP SAMM domains

Finding the root cause of component vulnerabilities and missing designs within specific assessment streams.

#5 about 4 min

Generating granular scores and creating improvement roadmaps

Using assessment results to identify organizational blind spots rather than fixating on absolute metrics.

#6 about 10 min

Conducting an effective SAMM interview and self-assessment

The logistics of setting up external interviews, guided self-assessments, and utilizing the provided spreadsheet toolbox.

#7 about 6 min

Common pitfalls to avoid during maturity assessments

Why organizations should refrain from comparing teams directly and instead focus on application-specific contexts.

#8 about 6 min

Audience Q&A on maturity assessments and external consultants

Audience questions around team size requirements and mitigating bias during internal security assessments.

#9 about 7 min

Embracing DevSecOps and automating the software development lifecycle

Shifting security left by integrating early automated feedback across code, containers, and infrastructure.

#10 about 5 min

Analyzing risks in open source and transitive dependencies

Understanding how the scale of nested project dependencies expands the vulnerable surface area of applications.

#11 about 10 min

Demonstrating a cross-site scripting attack on vulnerable inputs

Bypassing a markdown library's basic sanitization logic to execute a malicious payload.

#12 about 10 min

Fixer automation and in-editor software composition analysis

How developer-focused tools integrate directly into the IDE to detect and remediate vulnerabilities instantly.

#13 about 7 min

Integrating SAST and container security into developer workflows

Scanning proprietary code logic and base container images to block vulnerabilities before entering production.

#14 about 5 min

Securing environments by scanning infrastructure as code

Preventing exploitation by continuously monitoring configuration files and tracking infrastructure drift over time.

#15 about 6 min

Using financial data to advocate for security integration

Convincing technical leadership that fixing vulnerabilities early is exponentially cheaper than managing production breaches.

#16 about 13 min

Q&A on security automation and building champions programs

Final questions covering vulnerability capability, log4j tracking, and cultivating an organic security culture.

Matching moments

13:13 min

Answering audience questions on practical application security

Thomas Konrad · World Congress 2021

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE