Welcome to the first sprint of OneHourAppSec – we’re so thrilled to have you here with us, dedicating your time to application security. How good!
This sprint, we will lay the foundations for the work ahead of us. Our sprint goal:
- Understanding what software you have so we can plan to secure it
- Understanding the concept of security debt and making sure we can track it
- There is a lot to do but we will do it in small chunks to make it more manageable.
Let’s get into it 👏
Activities
📽️ [VIDEO] Introducing Sprint 5 (2 minutes)
Welcome to sprint five, where we dig into our plan for the next two weeks and the importance of choosing our 3rd party components wisely.
📽️ [VIDEO] What is supply chain security and what does it have to do with you? (5 minutes)
In AppSec we like to invent fancy terms for things, today we will look at one of these “supply chain security”. What does this mean and why is it important to us as software developers?
📑 Create and try out your own library selection process (35 minutes)
Now that you understand what to look for, its time to create and try out a process for reviewing new libraries in your context. Use our helpful template as a guide.
📽️ [VIDEO] Interview: Life as a vulnerability researcher (8 minutes)
Meet Selim Enes Karaduman, a professional software vulnerability researcher. In this short video they explain what their role and the importance of keeping our 3rd party software safe.
📽️ [VIDEO] Watch-along - Reviewing a 3rd party library with a security lens (10 minutes)
Join Laura as she reviews a potential 3rd party library for her project and shares what she is looking for from a security perspective.