Loading…
Attending this event?
Tuesday, June 25 • 9:00am - 5:00pm
2 Day Training:Building a High-Value AppSec Scanning Programme

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

**Training tickets are a separate ticket purchase from a conference ticket**
Student tickets are only applicable for conference dates.


You bought the application security tools, you have the findings, but now what? Many organisations find themselves drowning in “possible vulnerabilities”, struggling to streamline their processes and not sure how to measure their progress. If you are involved in using SAST, DAST or SCA tools in your organisation, these may be familiar feelings to you.

In this course you will learn how to address these problems and more (in a vendor-neutral way), with topics including: ● What to expect from these tools?
● Customising and optimising these tools effectively
● Building tool processes which fit your business
● Automating workflows using CI/CD without slowing it down.
● Showing the value and improvements you are making
● Faster and easier triage through smart filtering
● How to focus on fixing what matters and cut down noise
● Techniques for various alternative forms of remediation
● Comparison of the different tool types covered.

To bring the course to life and let you apply what you learn, you will work in teams on table-top exercises where you design processes to cover specific scenarios, explain and justify your decisions to simulated stakeholders and practice prioritising your remediation efforts.

For these exercises, you will work based on specially designed process templates (which we will provide) which you can use afterwards to apply these improvements within your own organisation.

Be ready to work in a group, take part in discussions and present your findings and leave the course with clear strategies and ideas on how to get less stress and more value from these tools.

Speakers
avatar for Josh Grossman

Josh Grossman

CTO, Bounce Security
Josh Grossman has worked as a consultant in IT and Application Security and Risk for 15 years now, as well as a Software Developer. This has given him an in-depth understanding of how to manage the balance between business needs, developer needs and security needs which goes into... Read More →


Tuesday June 25, 2024 9:00am - 5:00pm WEST
Feedback form isn't open yet.

Attendees (5)