Apollo Clark -- Malicious User Stories episode artwork

EPISODE · May 22, 2018 · 22 MIN

Apollo Clark -- Malicious User Stories

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you turn a security requirement into something a development team can build and test? Apollo Clark explains malicious user stories: short descriptions of what a particular attacker should not be able to accomplish. Speaking at the Source Conference in Boston, he connects these stories to business goals, regulatory requirements, and automated tests in a delivery pipeline. Apollo then steps back to define DevOps through values, feedback, and continuous learning rather than a shopping list of tools. The discussion follows those ideas into practical automation with Gauntlt, reusable security checks, containers, and infrastructure deployment. He shares lessons from working with executives and engineers, arguing that security succeeds when teams agree on outcomes and translate them into repeatable technical practices.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Apollo Clark:→ Apollo Clark on GitHubMentioned in this episode:→ Gauntlt→ The DevOps Handbook→ TerraformFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Malicious user stories with Apollo Clark01:41 Apollo’s security origin story03:14 From user personas to malicious user stories05:12 Writing testable attacker-focused outcomes05:50 Translating regulations into security stories07:22 Integrating the stories into DevOps08:37 Defining DevOps through values and the three ways11:59 Putting security into automated delivery13:00 OWASP contributions and Gauntlt15:35 Running security checks with containers19:10 Gauntlt’s direction and practical limitations19:39 Automating infrastructure deployment20:38 Start with what your organization values

Episode metadata supplied by the publisher feed · Published May 22, 2018

Embed this episode

How do you turn a security requirement into something a development team can build and test? Apollo Clark explains malicious user stories: short descriptions of what a particular attacker should not be able to accomplish. Speaking at the Source Conference in Boston, he connects these stories to business goals, regulatory requirements, and automated tests in a delivery pipeline. Apollo then steps back to define DevOps through values, feedback, and continuous learning rather than a shopping lis...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Apollo Clark -- Malicious User Stories

0:00 22:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 22 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 22, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!