Overview
Discover how to integrate security seamlessly into Continuous Integration and Continuous Deployment (CI/CD) processes in this 24-minute conference talk from Converge 2015. Explore the importance of early security implementation, static analysis tools, and security automation. Learn strategies for effective communication with developers, the benefits of centralized security components, and the role of encryption in secure CI/CD pipelines. Gain insights on making security responsive and efficient, ensuring that even busy CI/CD teams can prioritize and implement robust security measures.
Syllabus
Intro
Continuous Integration Continuous Deployment
Where Does Security Fit
Static Analysis Tools
Early Security
Security Automation
Responsive
Security KoolAid
Developers are not getting the message
Centralized security components
Encryption