appsec, ritalin, and failing fast ken johnson
introductions ken johnson ginger ninja also known hangs out on github, a lot
overview what this talk is about story survival guide a work in progress
Live in more than 647 markets around the world More than 60 million members worldwide, 25 countries on 6 continents 63 million vouchers sold to date Diverse offerings include daily deals, escapes, families, adventures, instant, gourmet Over 4,900 employees worldwide Updated January 23, 2012
week 1 – org chart
weeks 2, 3 - scope
week 4 – contact list, IR
week 5 - environment
week 6 – dev tools
week 7 – access
week 8 – time for QA
week 9, 10 – build it
week – metrics & baselines
weeks 15,16 – data classification
week – threat model
week 20 – training
hiring
who to hire
communication
21 Not. Role. Models. Sees something cool outside Training for a “floor- staring” Competition?
tools
friendly advice
Do NOT call someone’s baby ugly
Have a SOLUTION …don’t just say no
compliance is tangible
fail fast
Failed tests are better than none at all Realize a failed test quickly Don’t push it to the brink know when to quit, don’t be afraid
incidents
Define what constitutes “AppSec”
wishlist
Questions?
Thank you, Stay Hungry!