Persectives on the "Sec" in DevSecOps w/ Tanya Janca episode artwork

EPISODE · Apr 16, 2019 · 44 MIN

Persectives on the "Sec" in DevSecOps w/ Tanya Janca

from The OWASP Podcast Series · host The OWASP Podcast Series

If you've read the Phoenix Project, you'll remember Brent, the indispensable cog on the operations team. Brent was a good guy, he wanted to do the right things, all of the right things, but was pulled in all directions because of the lack of a unified plan for the company's project workflow. But what if Brent didn't want to do the "right" thing? What if Brent was more interested in the convenience of getting his work done than he was in the overall health and output of the project. What if he deployed to production without checking into SourceSafe, not just once, but for years. From Tanya janca: I went to our trusty code repository, took a copy of the most recent code. I went looking for the bug, and I couldn't even find it. And then I'm running it locally, and I'm looking at the real one in prod. And they're completely different. I'm like, "What would have happened if I had pushed to prod? If I fixed that bug, and pushed to prod, and not noticed the difference?" And he's like, "All my work would have been gone. That would have been your mistake." I'm like, "Are you kidding?" He's like, "It's just easier if I check it in directly, if I just edit it right on the web server. It's just easier for me." I'm like, "Oh. Is it easier to do a shitty job? No. No, no, no. In today's episode, Tanya Janca, Cloud Security Advocate, Microsoft, expands on her just published article, "DevSecOps: Securing Software in a DevOps World", clarifying each of the 5 tactics she uses to integrate not just security into the software development process, but how to manage people as part of that process. Have a listen...

Episode metadata supplied by the publisher feed · Published Apr 16, 2019

Embed this episode

NOW PLAYING

Persectives on the "Sec" in DevSecOps w/ Tanya Janca

0:00 44:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The OWASP Podcast Series?

This episode is 44 minutes long.

When was this The OWASP Podcast Series episode published?

This episode was published on April 16, 2019.

Can I download this The OWASP Podcast Series episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!