2023-10-15 –, WestIn - Partenkirchen
Tools are helpful to enable DevSecOps, many challenges and pitfalls highlight the need for a cultural shift. Explore issues such as security resistance, conflicting KPIs and organizational silos. Real-world examples and best practices will provide actionable insights to overcome these obstacles.
In today's fast-paced environment, teams are constantly aiming at delivering code, features and applications at an unprecedented speed. Agile and DevOps have heavily contributed to the increased go-to-market speed. However, this rapid development often neglects crucial security considerations, leaving systems vulnerable to cyber threats and compromises. DevSecOps is an approach that aims to bridge the gap between agility and security, by combining development, security, and operations.
Does this sound too good to be true? Are you wondering what could possibly go wrong?
Oftentimes there is a gap between theory and practice: this talk aims to explore the good practices for implementing DevSecOps and challenges associated, emphasizing the critical need for a cultural shift to foster its successful adoption. The challenges include security people being the fun police, developers being really lazy at times, but also the lack of awareness and education, different KPIs in the teams and organizational silos. We will examine real-world examples and best practices to provide practical insights into overcoming these obstacles.
By attending this talk, participants will gain a comprehensive understanding of the concept behind DevSecOps, the challenges associated with the implementation and learn practical techniques to initiate and sustain a cultural shift. This talk is intended for development, operations and security experts. They will leave equipped with actionable insights to effectively integrate security into their practices.
Application Security, Secure Development, DevSecOps
Jasmin is an experienced application security professional and Global Product Security Manager at Leica Microsystems. She gained extensive experience in organizing and implementing secure development programs, DevSecOps, and secure SDLC across different clients while working as a consultant. Her passion is to build bridges between cross-functional teams and finding new ways to improve collaboration. She likes working with people and technology, this has been the constant in her professional career and education.