fediversity_website/content/evenementen/nluug/voorjaarsconferentie-2019/talks/reinoud-van-leeuwen-built-in-security-in-an-agile-online-software-development-environment.md
2023-07-29 17:17:34 +02:00

1.5 KiB

categories date description layout tags title speakers presentation recording
presentaties
2019-05-23T10:31:43+02:00 event-talk
security
agile
development
Reinoud van Leeuwen - Built-in security in an agile online software development environment
reinoud-van-leeuwen
filename
2019-05-23-reinoud-van-leeuwen-built-in-security-in-an-agile-online-software-development-environment.pdf
platform url
youtube https://www.youtube.com/watch?v=FmblGoE4yyI

Abstract

We live in a fast-moving world. It's not uncommon in modern software development environments to do hundreds of releases in a microservices-based online application each week. Sounds great for management. But how do we keep it secure? Even when the programmers don't build new security holes themselves, we are dependent on lots of moving parts that are not built in-house.

This talk will look into the possible risks and some solutions:

  • keeping track of CVE's

  • scanning of repositories

  • building small (and efficient) containers

  • test containers and VM's against a security baseline

  • having procedures in place to quickly fix things during incidents

Biography

Reinoud has been involved in Internet hosting since the early 90's. After being involved in the organisation of several big hacker conferences (HIP 1997, HAL 2001, WTH 2005), and working for a major dutch ISP (XS4ALL), and one of the major classifieds websites in the Netherlands (Marktplaats), he is now working for a security company called Tekkamaki.