Reinventing Cybersecurity: Tales of Rebellion and Resistance | DevOps Connect 2022
Tracy Bannon of the MITRE Corp, Breanne Boland of Gusto, Jasmine Henry of JupiterOne and Coleen Shane of Quick Quack Car Wash come together at DevOps Connect 2022 to navigate the human and technical elements of shifting security left.
Transcript
So today I'm going to be talking with three contributing authors who are all practitioners in the DevSecOps space. We were all part of this recent Reinventing cybersecurity book, which is a compendium of essays by 19 women and non-binary security practitioners. And a two focuses today.
I was hoping to talk to my co-panelists about the work that they do as well as the experience of being part of a community Book Project. And I wanted to start by having a panelists introduce himself and their own words in a little bit about what they do. As well as our chapters.
for it Hello, my name is Coleen Shane. I'm a network security engineer for Quick Quack Car Wash. My chapter I think was a little more on the kind of social or human aspect I think of cybersecurity and you know kind of what we can do to network and socialize and might just make connections in relationships.
Hey, I'm Breanne Boland. I am currently a security partner on the product security team at Gusto before that. I did Enterprise security stuff.
I was an SRE for a while in an infrastructure engineer and before that for a bunch of years. I was a writer and an editor. So when the chance came up to do a project like this, I was like, oh wait, it's all of my talents at once.
Let's do this. So super exciting. Good point so my joking title for my chapter was your terrible security engineers at the real P0, but I wound up calling it.
It's about to be making a culture of yes, basically so that your security Engineers don't get in the way of the work. They're allegedly trying to do by being really difficult to work with. And I lay out ways to do that and ways to guide a culture back toward.
Yes, if you've drifted toward no, which can happen way more easily than anyone would like. Hey, I'm I'm Tracy Bannon. I am an architect and an engineer.
So I come at this a little bit from the opposite side of it. So security is always been something that at least for the last two decades that I had to deal with working in the government space. So do a lot of stuff with the state and local government.
Now, I focus on federal so when I got the opportunity to lean in on this book, I jumped right at it because I wanted to bring that other perspective to it. And that's what my chapters about my chapter talks about my journey trying to get an Enterprise to integrate. How do I get the developers the delivery team to actually talk to security and not be haters how to get security team to actually come to the table and not treat developers like a bunch of thugs and ogers know anything and there were a lot of challenges that were indigenous.
They were already there things that were culturally there things that were there financially just an entire structure and culture that was built around security is over there. They're the Protectors of Pride and everybody else is over here. So yeah just excited to be up here with My co-authors and I love meeting all these folks.
We've been talking for a long time, but never met face to face. Thank you, so that and just as a reminder at the book signing is. A book copies are complementary.
I really don't want to Lug them back downstairs. I'm still sweating from getting them up here. So please yes, please come and get a book and say hello.
So the theme this year of the RSA conference is transform and I feel like that aligns really well the work that we do. as Engineers as Architects as security practitioners So I think I was hoping to start off with kind of a broad question for the entire panel, which is so what are some of the transformation themes that you are currently dealing with in your work? Culture, it's all about culture.
Now. That's that's the the theme everywhere right now is we're realizing that it doesn't matter about the Frameworks. It doesn't matter about the tools you're hearing it again.
And again here this week and these different sessions that it is all about the people somehow in this process of rushing so fast, we forgot about the human aspect of it and I'm seeing that the transformation taking it from uppercase to lowercase is another theme so don't be so focused on having a digital transformation office or security transformation office worry about getting stuff done and I censored myself there from what I normally say, so worrying about getting stuff done and you know at the end of each one of the sessions that you're seeing this week people are telling you how to actually go and do things they're telling you what to do in the next month what to do in the next, you know, two weeks six weeks. What have you what to do in the course the next year. I think that speaks to the theme as well.
We need to stop thinking about it esoterically. More Naval gazing and actually do stuff. I would say the biggest theme of transformation in my work right now is figuring out scale on my team.
We've been moving gradually from wanting to talk to everyone and get into you know, the software development life cycles really as possible get in when it's just design and code hasn't been written which is great and it's important and it makes things work really well and also, you know, what do you do? If there are three security partners for a company of about 2,800 people. It just doesn't work that way all the time.
So we're doing a mix of talking to people individually, but also working really hard to find the themes that keep coming up. We're very lucky and that the collective unconscious of our company seems to be giving us good answers because we keep seeing the same problems coming up over and over which is you know, the joy of security nothing ever really stops being an issue. You just kind of learn deal with it every day.
That's a lot of what we're doing is surprised. I read a lot of documentation. It's one of my favorite things to do and just looking around to figure out what the next best problem we can do to address that way so that we can deal with the good weirder more bespoke things in an individual way.
And I do devset ops at us, you know startup you're not really there for the money or the the good hours like you're there because you're chasing scale and my in my personal experience go ahead. So for me, I agree with the culture. It's building relationships.
I think within the other teams and you know out for me it's outside of it like the marketing department sales department that kind of stuff. You know, they just want to they have a job they want to do they want to do it well and they go out and they find these fancy tools and it promises them that it can do their job for them and they want to implement. Well, you know, that's great if they come to us first and discuss it and we can you know, kind of work out a plan but you know often times, you know, this solution is already been purchased and you know, we now have to implement it.
So for me, it's trying to get that culture built. There's relationships built with the other teams to where they start thinking about security all the time. Released their worried about what a security you're going to say to us when we bring the solution up and also getting the higher levels to start thinking about that.
Hey, that's great. Did you run that by security? You know, what a Securities take on that.
So I definitely building those relationships and trying to get everybody to not look at security as the department of know the the roadblock, you know, putting the feet in the sand for me. I think I really like to look at it. It's weird a department of how can we make that happen for you?
I would like for you to come to me and say hey we found this great solution and it does X Y and Z. How can we do this? Can can you make this happen for us to me?
I would love to just bend over backwards to to you know, fit their needs and you know find a solution for the business but you know as a team working, you know collaboratively now just want to add something on when we say culture. There's another aspect and I heard it in some of the things you were saying and that's empathy Like the and whether your business whether you're security whether I don't care where you sit that getting to know each other and understanding walking a mile in their feet right or in their shoes rather while understanding better where they're coming from also is I'm I'm experiencing that as a theme when we're trying to get people together and have those conversations. Sorry for my clumsiness.
It's my I knew I was going to spill something or knock something over I think. Bit my chapter. Actually, I am kind of big on this idea that developers are now Securities main internal customer.
It is a huge chunk of our job to keep them happy. As much as possible. I'm actually going to direct my next question to Tracy.
You're somebody who's spent your career Consulting most recently for federal government organizations. Can you speak to some of the challenges you've encountered when you're trying to build a new culture of SecOps at a client organization? Doing things for a long long time.
It doesn't matter if they've got a new leader who comes in with really amazing bright ideas the muscle memory of the organization overwhelms them so as much as they will put memos out policies out try to get structures to change that muscle memory just pulls everything back. You know, I jokingly say there's mean time to command change and there's truth to that especially on the defense side of the house because sometimes they'll be in their role for only a year too and then they'll be rotated out to another location. We'll how long does it take you to take control over an organization that has a hundred or a thousand or ten thousand that are within it.
Well, it takes a while and so the first six months you're getting your feet underneath you you maybe have eight to ten months a little bit more where you're really starting to get effective and then you're starting your transition out. So it really does have a massive impact. I'd say that all of the things that we've talked about being sick versus Dev the very, you know the lines Sand also a lot of the policy in my world policy is just everywhere at every level anything that you want to do has a policy associated with it.
And there's usually layers of policy. I call them scabs and scars right from things that have happened throughout the the years and that also impacts. So you want to come in you want to change and how do you break past that muscle memory?
Well, you need a set of leaders who are willing to jump in and Champion truly Champion. You need middle management who actually have enough bandwidth to support what's going on, right? That's one of the big things that happens in government is the entire middle is is just hammered.
They're slammed. They are constantly putting out dumpster fires. And then you have everybody who's at the Hands-On that wants to do things in necessarily getting the TLC that they need in order to be able to contribute.
So it's it's unintentionally institutionalized now, I will say there are some bright spots there are things going on in some areas like the software factories that you'll hear about and DOD. Where they're starting to do some of these things right? I can't say that all of them are doing everything right right now but they're experimenting and they're looking at different kinds of contract mechanisms to even allow them to experiment.
So, how do you break past muscle memory while you got to bring in enough new thinking enough new thinking one person is not enough. There's some statistic that says that if you take the same organization and say we're going to change and you don't have enough change in the people who are there that you will not be able to exact that change right? It's like I say and tomorrow I'm gonna become an Olympic Athlete.
These are all the things that I'm gonna be doing. I'm gonna eat this way. I'm gonna sleep this way.
I'm gonna do these kinds of exercises. Yeah. I'm not gonna happen if it's just me, right so it's gonna take a whole lot more than that.
Thank you. We'll said Brianne. Can you speak to your role a little bit as a security partner and some of the tools that you use to move human attitudes?
Yeah, absolutely. So I'm actually in the process of digging into the broader definition of a security partner because I've been seeing it come up at different companies and I was drawn toward it at Gusto because it is a more consultative model, which is I've done Consulting before and I honestly really like getting to dive in and figure out what's actually going on versus what people think is going on, which a lot of times is very different. And in this case.
I was drawn toward it in part because of our siso flea Frederick Lee who is a fascinating Delight. He did a talk at besides here in 2020 called sharing Securities Legos and it was a whole model about wanting to share tools rather than a security model that's existed before of just kind of hoarding. I always think of like an angry little squirrel Dragon like these are our tools and our knowledge and we'll dispense it when you need it and that was completely it's the opposite of what anything that I want.
So having him come out strong and just be like, no we don't do that. We're here to enable teams and to support teams and to help people do things that they want to do and Was exactly what I wanted from this job. So the tools I use tend to be more person to person which is how we find the areas to scale.
So one supports the other and my favorite things when I first meet with someone and most often I meet with product managers, but I do work with engineering managers and Engineers, too. But I'll ask them when we're establishing the relationship what their previous experiences with security work, which is very much like tell me where it hurts because some people have only had like wonderful glittery experiences with security and like that's wonderful. It's one of my favorite things to hear like cool.
You met security benches like, yes, perfect. Let's just continue the conversation but if they've previously been at an organization where security acted more as a proofreader, which is a job I've had and I do not want to have again. I'm good.
We have to start dialing back a little bit and I make a point of telling them. I'm here to support them. I'm not here to approve or deny.
I'm just here to help them identify risk and take it on consciously instead of you know, three months on getting a terrible call in the middle of the night that everything is very bad and on fire and it's time to wake up. you know that's still is going to happen occasionally because you know software I think we've all met it, but I wanted to be something specific that they opted into rather than a terrible surprise that no one warned them about so I go in just offering support offering help. And I also very often say that I want to be an educational resource for their their engineering teams too, like my goal aside from let us all reduce risk and have a better life working is my hope is to support Engineers to get something extra on their resume.
So they get a much cooler job next time if they want to like I want them to be able to say. Oh, yeah. I know threat modeling because I work with security partners and it's all part of the general campaign to incentivize like I want them to go.
Oh cool I get to talk to security. I'm going to get something amazing out of this. So yeah, I aim to meet them where they are understand where the old wounds are and be mindful of that maybe help try to heal them but also offer them something they might not have had before and might not have had otherwise so that they are always happy when one of our many meetings comes up on their calendars.
Said was kind of interesting was that when devs get to go talk to security. Still sounds like we've got devs and security we've got so there's there's still silos. They're all and the way that we're Matrix the way that we work together is always going to we're always going to be accountable to somebody we're always going to be an affinities.
But how do we how do I make it so I'm not going to go and talk to security but we naturally just connect like we've gotten we've built a relationship together. So I don't have to be we're having a meeting with security in two weeks. Like I could just pick up the phone or we can hop on a call or meet in the you know in the lounge.
I love that question. Thank you. A big part of that is I try to make it clear that my job is to meet them on their terms.
Like I tell them like you cannot bother me too much and you know, fortunately my job description supports that like obviously not everyone can do that. But I tell them like, I'm happy to meet with your team. I will set up something recurring so that it's deeply ordinary.
Like that's the thing I go for is talking to us is ordinary. It's not special. It's not.
Oh, it's not. Oh, I'd better do my homework extra. Well because security I want it to be so normal to talk to us.
And so that's since we don't embed. I mean, I think honestly embedding is the best solution is like you have a security person who's just part of your team. It's just not all company sizes can support that.
So instead I just work to normalize it as much as I can just saying. Hey, I will always be glad to hear from you. I will always help you.
However I can and if I'm not available, I will still connect you to someone who can help you out just to know that if they talk to us, they will get what they need. I tend to treat you as much as me so in the same way that for me for some teams. I'm the Chief Architect.
The lead engineer. I'm a Smee into them. They've got their daily.
I'm not on in every scrum meeting. I'm not in every Sprint planning. I'm not everywhere at all times.
It sounds like we probably have kind of similar roles where we're making ourselves really available, but not hanging with them all the time Kind of a Funny Story. I've known Colleen for about a year and for a long time. I didn't know we're calling works and I feel like my my speculation ran a little bit wild and it was a distributed National Organization with a lot of locations.
And I wish I could say that I had some great theories about just really dramatic ideas. I thought it was Telecom, but it's not. However, you know that said you're working this kind of distributed National model with a lot of consumer facing locations given that model how have you worked to build relationships between security it and engineering?
That's an ongoing process. What I've tried to do is, you know meet as many of the members of the other teams as I can to try to build some relationships with them and get a rapport going. um, gosh, I think I can't emphasize enough on building those relationships and kind of getting that collaboration going because what I am looking for from them is them thinking about me, right?
You know, if they send something weird or something odd, they're gonna send me an email or give me a call just as you suggested to me. I think that's better. And you know, I know that for a long time to help desk was like, you know, don't call us at a ticket put in a ticket, right?
So, you know, I think it and Security in general has got this kind of And I guess bad rap or I mean we kind of gave it to ourselves of being like, you know, right? I'm too busy, you know, don't call me put in a ticket. You know and that's understandable.
But you know that also kind of kills the relationship with that person because they thought well, you know, I thought we were cool or I thought we were friends or I thought we had this relationship to where I could reach out to you when I thought something was you know odd and you're always going to have the ones that are the problem cases that you know are gonna call you for every single little thing. But to me, I think that is worth dealing with holding a hand or two every now and then To you know, invoke that culture throughout the organization to where everybody is like hey. You know, I know I can reach out to Colleen and ask her a question and you know, they they're starting to do that.
I need to reach a little deeper into some of the other teams, of course, you know marketing that kind of thing to where they'll reach out to me when they have a question or you know, but that's the steps that I'm taking and the culture that we're trying to build within our organization. And you know, I can't stress it enough to try to do that to try to not be that roadblock. Stop putting your feet in the sand on everything and making everybody think that you're too busy you're too important for their problems because they're not going to come to you with them after that.
They're just gonna submit a ticket and just let the system take care of it. That's such a good answer. I feel like I want to run over and hug you there's a there's a story in my chapter.
I think that's the kind of lines that well which by the way, I think it's it's actually helpful and healthy that in many cases it starting to report security that was the case of my last organization my current organization. Um, I think Jason Shannon Netflix may have been one of the first Seasons who kind of own security. But anyway, I wrote a policy that said if you have your laptop stolen due to extremely negligent Behavior four times in a calendar year, you may have to pay for it and my phone just started blowing up and I was actually I kind of counted as a win because folks weren't complaining to their manager.
They were complaining to my manager. They weren't complaining about me to HR. They were talking to me.
They were calling my personal number and and saying I have feelings like there's a lot of car break-ins and so then we got to have a conversation about maybe don't leave your laptop in the car. If you can avoid it or put in the trunk or put it in the bank that doesn't look like laptop bag. It was it was great.
I'm actually gonna jump ahead a little bit sake of time and I'm gonna say what advice would you give to aspiring first time authors? And what did you learn from writing the screen bending cyber security? Yeah, I have a lot to say about this for the sake of everyone else getting to talk.
I'll keep it brief. I did a talk at pancakes con earlier this year. That was a it was how to do server osent using command line tools and how to write your first novel pancakes con.
They have you write something that's related to work into something you love. All the talks are worth seeing learned a lot about leather work didn't expect that. The biggest thing that I find troubles people when they're writing something like this.
They've never done it before is they want to self edit and Human nature like you want to really do this well, and that can completely keep you from being able to type words because all of our words are imperfect and it's just true we can polish them and they'll get better by drafts and like one of the reasons I was so excited to sign on to this is that we had access to a copy editor and having been a copy editor having someone edit me is among one of the finer luxuries in life. Oh, it's the best like someone completely dedicated to making me look more. Awesome.
Yes. Thank you. My advice is to practice mindfulness as you write.
And this is so specific. But just when you type just know this is not I think of it as you know, we are going to try to make a dress right the first thing you type is not the dress. The first thing you type is maybe it's some cotton that might become thread.
Like there are stages. There's cotton. There's thread there is cloth there is figuring out the pattern and then eventually there's the final garment and you have to forgive the fiber part.
It is necessary and I would argue it is beautiful because it's where you start figuring out what you actually care about. So practice himself forgiveness understand that the first try does not have to be the best try and remember that you probably wouldn't expect that of anyone else on Earth. So, please do not expect it of yourself because if you get the chance to do something like this, I want you to LEAP on it if it's exciting to you.
This has been fantastic. This has been a wonderful career upending like wonderful experience. I'm sitting here doing this.
Wonderful. I am an amazing company. It's wonderful.
So mindfulness writing is not the easiest thing for everyone but it gets easier as you go and just be very very gentle with yourself when you start because you will get there but you know all mountains have Foothills. It's okay. Thank you.
My advice would be to you know, kind of fall along the lines of what she said to just do it. Just put the words down, you know, go back and reread them, you know, and to me that's what I did. It's in it's kind of funny because You know, they told us about the book and I said, you know, what are the, you know constraints and they told me the page numbers and then the time frame.
And you know, so I wrote you know, all these words and I submitted it like, you know that day really yeah. Yes it because I was worried about me being the one that would drag the rest of the team down. So I wanted to get something there to where they could give me feedback and say hey you're going the right direction.
You're going the wrong direction. So that that was really helpful for me to just get it down. But you know, I got it submitted and then you know at that point I felt good about myself because I had something that I was somewhat proud of even yet even though it had yet to be edited.
So I kind of became a truly here for the rest of the team and like yeah, great you can do it and you got this and you know, it's like, you know trying to bolster them and give them a little bit more confidence to help them get through be like, hey, look I did it. If I did it you could do it too. You guys are much better authors and myself.
So if you could do something on a on a team like this, you know if you're first starting off, Highly recommended because you've got other people that have other experiences or they've done something similar before, you know that can lend that experience and some advice. I'll just just for contacts Mark Miller's model for these Community authored books is that you you go and find experts and their field around a centralized topic which in our our case. It's the the reinvention of your craft and your career the work that you're doing today the work that you're doing tomorrow planning for tomorrow, and then you're career Journey as well.
I know that Mark has done these books and as little as three months, this one is a little bit closer to five into finish for a couple reasons. It's huge, you know 19 authors and then you know, we almost did kind of two rounds as well. Go ahead Tracy.
Oh my god. Well everything they said and so I like I like to talk just engage. I'm kind of on the shy side believe it or not.
And when I got the invitation for this I actually turn to my partner to my husband such I do this of course, but I like to talk. I don't really Right, and he said actually you do you you write the way you speak and you have a story to tell so just tell a story and those words in combination with a shared slack Channel and late night phone calls was really inspiring because I I got to find my own story in this but I also got to experience other stories from other points of view and I would highly Advocate it if someone were to come to you and say go write a book. But how about write a chapter to a book?
Oh, I'm all in now. Am I thinking about writing a book on my own not this thick maybe something really skinny, but to take further the storytelling and being able to help other people to grow from it. So I would if anybody ever ask you.
Hey, you want to jump in try it? What do you have to lose worse thing is the copy editor says returns it to you and says you need to make a couple more changes on it. Very much like a opportunity to learn right there.
I mean to improve on your next chapter your next book, so Absolutely. Yeah, I think I've been really blessed and grateful that in the it's been about a month since it's both came out. It's it's sold really well, which is not to say that we've we've cut a profit on it.
You do not cut profits on books and this this day and age but we've had a great reception and it's it's really touching, you know, it means a lot to me when I'm asked to dedicate a book to you know, a girl in high school who's considering pursuing a career in stem or when women who have perhaps 20 years more experience than I do come up and it means a lot that they're represented because that was not something they had perhaps earlier in career. I'm gonna leave some time at the end for questions from the audience in case there's any however, I want to ask what what advice would you give yourself five years ago what career advice? Good, I would probably say perseverance and stick with it.
You know, we all have setbacks. I you know share mine pretty publicly on Twitter. So it's about overcoming those so it's like I guess perseverance stick with it don't give up and you know, that's something that I actually you know had to go through in my mind yesterday.
So I'm gonna hop over and be the opposite end of the spectrum because I have too much stick to itness. I get two pig-headed that I can solve this even though it's a really toxic nasty situation. It could be a work situation.
It could be a particular client. I tend to stick with it because I'm Gonna Save it because I honestly want to do my best. I honest you want to help I do that way too much and five years ago.
I really wish I could go back five years and say, you know jump now change now because where I'm at now and the people I'm able to help now and the volume and the scale and the potential impact has really made a difference. So but your point of you got to be introspective about it and why you're there and what you're doing spot on coming. My answer is kind of between the two one is I would tell myself it is worth staying with it.
Yeah, I made career jump in 2015 after a couple of years of being very grumpy about the prospects and the editorial world. I lived in Seattle and realized I was starting to be priced out and was like, this is what I signed up for isn't fair and realized that my enduring interest in computers might actually really useful. So I would tell myself that it's worth keeping on because it's really hard sometimes but the other thing would be to seek out situations where I where the chief quality necessary is endurance.
I would like to start avoiding those because it is so tempting to be like oh if I just try a little harder if I'm just a little more perfect like You know, I grew up in the midwest you get told that stuff a lot. Sometimes it's really useful. Sometimes it is deeply toxic.
So I would go back and gently Advocate just saying like hey this thing that has felt terrible for six months is probably not going to feel awesome at month seven and that's okay just to turn around. So be a mix of just reassurance like there is a place for you which was a big deal when I was working to get out of editorial I went to ux school for a year, which actually is very useful for security and just thrashed around and I just I knew there was a place it just took me a while to find it and I kept thinking of it as the aspect like I'm just looking for the aspect. And it turned out the aspect was coding surprised.
People want to hire you for that. But the combination of the skills they had before with that are the things that led to amazing opportunities and sitting here today. That's what enabled all of that.
So yes keep on but also you don't need to keep throwing yourself at painful stuff. You have to go where love is served after a while. Before I open it up for questions.
I want to acknowledge the authors that are in the audience today. We have Ashley Lee marketing manager at Jupiter one who wrote the introduction. We have Carla son security engineer at gusto.
And I apologize if I mispronounce anybody's name Title Company. Genuinely Rachel Harpley. I am not entirely sure on which title you use.
advisor for info sec and we have Angela won the marofino a program manager at Microsoft. And then we have a number of authors that are not here currently maybe coming in later and we'll be doing this signing downstairs in some cases at 2:30 in Booth s 325. So I'm going to name them as well.
Amy deverse ebeneziah. long a Ford Allison jannata who sometimes goes by snipe Lisa Hull Joyce Huggins, Dr. Meg Layton Lafayette marpuri Rin Oliver Carlos sage and Aubrey Stern and the cover art is by a Ukrainian woman artist.
It's a commission. Her name is Lita Simon kova since we wanted to get a woman who was not too young and kind of looked determined since that is something that we all have in common. You too, so any questions for the audience?
Hi. I know nothing. About books.
So I apologize. I have to look at it after this. But I think listening to you, you might have some strategy for this use case that I have for you.
If any about 250 people it's a financial services company in Chicago. And on the seaso at the company been there about 20 years and my role is been to secure the company. Inside the company they're about a hundred developers and they build this product that's used by very large Banks across the world.
Well has never been one to to protect that product. Ironically. They're kind of on their own about security.
There's never been any guidance that they'll if I mentioned something they'll take they'll take some kind of feedback from me, but there's no official. any type of line of command you could say and I have this it committee that involves the director of this development team of these hundred people. He's on that.
And in terms of personalities, I don't have any problem with any of them but strategically in terms of kind of moving my my role in part from what I do to protect the company and move into this product and try to protect it better with this with this devops idea which to me is a little foreign. I understand it but never applied it. so I guess my question is from a kind of a strategic standpoint in terms of trying to get trying to convince them the benefit of getting in front of a security.
Protocol and design strategy versus having our clients tell us about the problem after it's deployed. By his way to begin that entire. Discussion and move them instead of being demanding and saying, you know, you better do this if we have a problem.
What is the best way that you've seen this work in companies that are trying to get this more mature? As I deal with this on a daily basis, first of all need to not dictate right and you've already said that you need to not dictate. This is something where everybody needs to have a shared sense of purpose and a shared sense of security security is everybody's responsibility the way that I normally go about this though is doing team building exercises.
I know that sounds kind of goofy and I'm not talking about cross your arms and fall backwards. I'm talking about doing things. Like let's take one module or one part of your current product and get together get the business together with the developer some of the developers with the security folks and actually do some verbal threat modeling.
I don't mean that you have to follow a really hard core methodology. I mean actually sit down and write some user stories and add on to and I think Alison Miller was talking about this earlier. She was saying write your user story, you know, as a user I would like to do acts so that I right that's your user story then add on And I need you to protect me from X by doing this for example, when I do a search, I want you to make sure that my search is not cached so that nobody can find out that I was looking for underwear.
I don't know I'm making something up right. So that's one way that you do it. You've got to build you've got to make sure that developers have training.
So something to Jasmine about a lot is the fact that we're shifting left. We're shifting a whole bunch of stuff left everything shift left. Well what shift left actually should mean is start at the earliest Point possible.
It doesn't mean that we just lob it on to the delivery Team without training them, which is what happens, right? We lob it on to them. So now our developers are supposed to be security Pros.
They're supposed to know something about security. I can tell you how much they know and it's not a lot and it's not for lack of want. So we're turning them into what I call security hobbyists.
So they're not getting secure coding standards. They should you as an organization sit down and figure out what you're secure software development life cycles going to look like if you're going to start to adopt devops principles sit down as a team and I don't mean it's coming out of a dictated office. I mean together sit down and create that sdlc together.
That's secure. There's a nist standard around this there's a lot of good guidance on it. But have the conversations as a team so that they're vested in what they're doing same thing with the coding standards get together and say which one what are these things?
Are we going to adopt? Why does it matter have them have skin in the game when you do that and I could go on and on but come up with a couple of initial creative ways that everybody is coming to the table to have co-ownership because until that happens, it's still going to be the Hatfields and McCoys, right? Generally, the the concept has been that the security designs are considered to be expensive nice to have and they don't get the product out the door to create profit, which is what the operational part of it does.
So, thank you. I think we have one minute. I think that we can probably thank the audience.
Yeah, they actually analysts you can ask you one question. What would you tell yourself or aspiring editors about embarking on a project like this that you couldn't have guessed out a year ago? Oh, well the older I get I think the more I realize that I'm typically right.
And I often need to just trust my instincts. You know, I think that my instincts in this project a couple different cases. We're really good.
There was one point in time where we decided to collectively decided to pause and move forward as a less homogenous group so that we could recruit a couple more authors because diversity and representation really matter and I think that my instincts are typically good and that when you get a lot of really bright well-meaning women and non-binary people together, I think some pretty magical stuff can happen.





