28
Julia Knecht | Adobe Systems @juliaamarieee SAASy SPLC

SAASy SPLC - AppSec EU 2016

Embed Size (px)

Citation preview

Page 1: SAASy SPLC - AppSec EU 2016

Julia Knecht | Adobe Systems@juliaamarieee

SAASy SPLC

Page 2: SAASy SPLC - AppSec EU 2016

About Adobe

SAASy SPLC - @juliaamarieee 2

CONTENT DATA

Creative Cloud Document Cloud Marketing Cloud

Community Marketplace Partners Developers

Page 3: SAASy SPLC - AppSec EU 2016
Page 4: SAASy SPLC - AppSec EU 2016

Now

SAASy SPLC - @juliaamarieee 4

Analytics Audience Manager

Campaign Experience Manager

Media Optimizer

Primetime Social Target

Page 5: SAASy SPLC - AppSec EU 2016

Goals

SAASy SPLC - @juliaamarieee 5

Page 6: SAASy SPLC - AppSec EU 2016

How• Get Buy In• Set a Baseline• Measure & Automate• Leverage Existing Process• Build a Community• Create Opportunities for Learning• Be a Service Organization• Add Value

SAASy SPLC - @juliaamarieee 6

Page 7: SAASy SPLC - AppSec EU 2016

People will do things for 1 of 2 reasons:

7SAASy SPLC - @juliaamarieee

Page 8: SAASy SPLC - AppSec EU 2016

Security as a Service

SAASy SPLC - @juliaamarieee 8

Page 9: SAASy SPLC - AppSec EU 2016

Product Engineering Team Buy-In

9

Product

SAASy SPLC - @juliaamarieee

Page 10: SAASy SPLC - AppSec EU 2016

Our Security Champions are…

10SAASy SPLC - @juliaamarieee

Page 11: SAASy SPLC - AppSec EU 2016

It has to be the product team –get champions

11SAASy SPLC - @juliaamarieee

Page 12: SAASy SPLC - AppSec EU 2016

Map: Security Certification Program

12SAASy SPLC - @juliaamarieee

Page 13: SAASy SPLC - AppSec EU 2016

Tactic: Competition: Before

13

A B C D E F G H IWhite Belt 99 95 99 100 92 100 96 93 96Green Belt 98 95 94 93 88 84 70 54 41

0

10

20

30

40

50

60

70

80

90

100

White Belt

Green Belt

SAASy SPLC - @juliaamarieee

Page 14: SAASy SPLC - AppSec EU 2016

Tactic: Competition: After (2 days later)

14

A B C D E F G H IWhite Belt 100 95 100 100 92 100 96 100 96Green Belt 100 95 100 100 88 100 96 100 68

0

10

20

30

40

50

60

70

80

90

100

White Belt

Green Belt

SAASy SPLC - @juliaamarieee

Page 15: SAASy SPLC - AppSec EU 2016

Set a Baseline

15SAASy SPLC - @juliaamarieee

Page 16: SAASy SPLC - AppSec EU 2016

Measure & Automate

16SAASy SPLC - @juliaamarieee

Page 17: SAASy SPLC - AppSec EU 2016

Provide Incentives

17SAASy SPLC - @juliaamarieee

Page 18: SAASy SPLC - AppSec EU 2016

18

"I know that well enough, Mr. Frodo. Of course you are. And I'm coming with you.”

"ButIamgoing toMordor."

SAASy SPLC - @juliaamarieee

Page 19: SAASy SPLC - AppSec EU 2016

PLC à SPLC

19SAASy SPLC - @juliaamarieee

Page 20: SAASy SPLC - AppSec EU 2016

Leverage Existing Process

20SAASy SPLC - @juliaamarieee

Page 21: SAASy SPLC - AppSec EU 2016

Security Team

21

training, threat modeling, hacking skills, security automation, checklists, sign-off, coordination, security monitoring team, talking to customers about security…

You have my bow

SAASy SPLC - @juliaamarieee

Page 22: SAASy SPLC - AppSec EU 2016

Services• Threat Modeling• Testing Automation • Security • Pen Testing Coordination• Best Practices/Training• Security Testing• Security Architecture Reviews• Customer Security Engagement

22SAASy SPLC - @juliaamarieee

Page 23: SAASy SPLC - AppSec EU 2016

Be a Service Organization

23SAASy SPLC - @juliaamarieee

Page 24: SAASy SPLC - AppSec EU 2016

Provide opportunities for learning & a Secure-Engineering Community

24SAASy SPLC - @juliaamarieee

Page 25: SAASy SPLC - AppSec EU 2016

Add Value

25SAASy SPLC - @juliaamarieee

Page 26: SAASy SPLC - AppSec EU 2016

Results

26SAASy SPLC - @juliaamarieee

Page 27: SAASy SPLC - AppSec EU 2016

LL Summary• Champions• Training• Existing Process• Measure• Automate• Recognize• Add Value

27SAASy SPLC - @juliaamarieee

Page 28: SAASy SPLC - AppSec EU 2016

Adobe Resources

28

Security portalhttps://adobe.com/security

Security @ Adobe bloghttps://blogs.adobe.com/security/

Advisories and updateshttps://www.adobe.com/support/security

Twitter: @AdobeSecurity

SAASy SPLC - @juliaamarieee