EPISODE · Sep 26, 2016 · 27 MIN
Chris and Robert -- Security in the Methodology
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one. Waterfall makes phase gates, documentation, and specialized reviews visible, but often delays feedback. Agile breaks work into smaller increments, uses user stories and acceptance criteria, and creates opportunities to test security continuously. The hosts discuss stand-ups, sprints, continuous integration, threat modeling, abuse cases, reusable requirements, and the difficulty of defining “done” when security work spans multiple stories. Their conclusion is not that one methodology automatically produces secure software. Security succeeds when its activities fit the team’s real delivery process and provide useful feedback at the moment decisions are made.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ Agile Manifesto→ Microsoft SDLFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Security in development methodologies02:33 Why organizations still use Waterfall04:07 Documentation and predictable phase gates06:01 Where Waterfall came from07:19 Applying security to each Waterfall phase08:40 Moving from Waterfall to Agile10:25 Testing inside every sprint12:09 User stories and acceptance criteria13:25 Stand-ups, retrospectives, and feedback15:00 Continuous integration and Agile16:49 What it means for a story to be done18:19 Fitting AppSec into Agile work20:32 Turning security needs into stories21:50 Testing authorization requirements24:25 Threat modeling and abuse cases27:21 Final methodology lessons
Embed this episode
What this episode covers
How should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one. Waterfall makes phase gates, documentation, and specialized reviews visible, but often delays feedback. Agile breaks work into smaller increments, uses user stories and acceptance criteria, and creates opportunities to test security continuously. The hosts discuss stand-ups, sprints, continuous integration, threat modeling, ...
Ready to play
Chris and Robert -- Security in the Methodology
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.