World Congress 2022 • Jun 15, 2022

Organizational Change Through The Power Of Why - DevSecOps Enablement

Nazneen Rupawalla

Why does application security constantly stall deployments? Learn how explaining the business context and empowering developer champions transforms security from a late-stage bottleneck into a seamless agile workflow.

Pause
Mute Enter Fullscreen
#1 about 4 min

Identifying bottlenecks in traditional software security approaches

Discover why centralizing secure development responsibilities within an infosec team creates friction and limited scalability.

#2 about 3 min

Establishing a center of excellence and security champions

How building a security center of excellence and establishing an empowered champions program drives cultural change.

#3 about 2 min

Embedding security controls into project management tools

Map security requirements directly into existing developer workflows utilizing standard issue tracking boards.

#4 about 3 min

Contextualizing the why and how of security requirements

Providing real-world threat context and specific implementation guidance helps developers understand the value of secure coding.

#5 about 2 min

Pairing with teams for continuous threat modeling

Mentor security champions in identifying system vulnerabilities using established threat modeling methodologies during product kickoff.

#6 about 2 min

Integrating security scanning tools early in the pipeline

Implement standard security tooling directly into the build and deployment lifecycle to prevent vulnerabilities from reaching production.

#7 about 3 min

Automating compliance tracking with customized project dashboards

Utilize simple scripting and webhooks to generate team-specific project boards and visualize real-time security progress.

#8 about 3 min

Visualizing organizational risks through a maturity model

Aggregate team-level security data into an overarching framework to facilitate meaningful discussions with governance forums.

#9 about 3 min

Nominating accountable security champions to drive adoption

Why asking technical leads to actively select members builds stronger accountability than relying on pure volunteers.

#10 about 4 min

Structuring implementation timelines and threat modeling cadence

Determine the time investment required to establish proactive security processes and establish cadence for threat modeling.

Matching moments

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

48 sec

Scaling knowledge through security champions programs

Stefania Chaplin · World Congress 2022

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE