Some approaches I've seen recently are @swagitda_ and @nicolefv D.I.E, Rugged by @RuggedSoftware, DoD's Enterprise DevSecOps Reference Design and STPA-SafeSec introducing safety thinking into #CyberSecurity engineering. Any other valuable frames you're aware of ? #wardleymaps
buff.ly/2CJWIL4 Chinese dualism of attack&defence meets @RuggedSoftware doesn’t make insecure software something that the Devs are to blame or the security team fails to assure. Insecure software is a symptom, not a cause. #cybersecurity
Just learned about the #RuggedManifesto (@ruggedsoftware) reading the chapter on #infosec in @nicolefv, @jezhumble and @RealGeneKim's "Accelerate". "I'm rugged, and more importantly, my code is rugged." Amusing but also thought provoking. Not the first great find in "Accelerate".
I'm doing some research for the DevSecOps Handbook due out next year. If you work with Devops, Cyber, ITSec and/or Information Security could you please fill out this survey. Thanks - surveymonkey.com/r/8GSCTYW - PLS RT
Best quote!
"I am a nice security professional, not a mindless vulnerability spewing machine. If I am to change this image, I must first change myself.
Developers are friends, not fools."
@matt_tesauro@AppSecEU@owasp#DeveloperLove