EPISODE · May 22, 2018 · 22 MIN
Apollo Clark -- Malicious User Stories
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How do you turn a security requirement into something a development team can build and test? Apollo Clark explains malicious user stories: short descriptions of what a particular attacker should not be able to accomplish. Speaking at the Source Conference in Boston, he connects these stories to business goals, regulatory requirements, and automated tests in a delivery pipeline. Apollo then steps back to define DevOps through values, feedback, and continuous learning rather than a shopping list of tools. The discussion follows those ideas into practical automation with Gauntlt, reusable security checks, containers, and infrastructure deployment. He shares lessons from working with executives and engineers, arguing that security succeeds when teams agree on outcomes and translate them into repeatable technical practices.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Apollo Clark:→ Apollo Clark on GitHubMentioned in this episode:→ Gauntlt→ The DevOps Handbook→ TerraformFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Malicious user stories with Apollo Clark01:41 Apollo’s security origin story03:14 From user personas to malicious user stories05:12 Writing testable attacker-focused outcomes05:50 Translating regulations into security stories07:22 Integrating the stories into DevOps08:37 Defining DevOps through values and the three ways11:59 Putting security into automated delivery13:00 OWASP contributions and Gauntlt15:35 Running security checks with containers19:10 Gauntlt’s direction and practical limitations19:39 Automating infrastructure deployment20:38 Start with what your organization values
Embed this episode
What this episode covers
How do you turn a security requirement into something a development team can build and test? Apollo Clark explains malicious user stories: short descriptions of what a particular attacker should not be able to accomplish. Speaking at the Source Conference in Boston, he connects these stories to business goals, regulatory requirements, and automated tests in a delivery pipeline. Apollo then steps back to define DevOps through values, feedback, and continuous learning rather than a shopping lis...
Ready to play
Apollo Clark -- Malicious User Stories
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.