Breach Prevention for Developers
As an information security professional, it’s critical to know something about how custom web applications are developed and the impact that has on application security. This guest lecture, given to infosec students and professionals at Kennesaw State University, covers what it takes to build security into a web application hosted in the cloud. Since security cannot be bolted on at the end, it walks through the tools available to include security as part of the development process, including user stories, abuser stories, and test-driven development that includes security tests.
Slides for this talk are available on Speaker Deck.