Some time ago I had the pleasure to speak at the BASTA!
Autumn 2019 conference. There, I promised to publish my
slides
such that they can be used as a reference for developers and security guys like
me. And with this blog post I would like to hold up to my promise.
Overall, the talk was about the challenges of “How to bring security into modern
DevOps processes”. Hence, I demonstrated how security can be integrated more or
less seamlessly into the modern agile software development workflow. I proposed
some risk-depended recommendations about which measurements should be
established, for example, within the CI pipeline.
A while a go Dominik and I gave an introductory presentation about SSL at the
BASTA.NET conference, a developer-oriented event held in Darmstadt twice a year.
At that time there were quite some enthusiastic participants but recently we’ve
also gotten some inquiries asking for the relevant materials. Although there’s
no recording of the session, we’ve decided to put the slides here for those
interested who didn’t make it to the talk.
Yesterday I was giving two presentations about Cloud security at
the BASTA! Spring 2013 Security Day. While my presentations
covered Microsoft Azure security considerations (which also included a part of
the Cloud security approach covered in our
workshops;
slides available
here) and some
major Cloud incidents (suitable to transport different messages about Cloud
security in general ;); slides available
here), I also
saw Dominick’s very interesting
presentation
about security aspects and changes in Windows 8. Inspired by that, we hope to be
able to publish another blogpost on those aspects with regard to enterprise
environments soon — most likely we won’t find any time for it before
TROOPERS 😉
Just a short notice today on some recent presentations from our team. As some of
you might know we regularly give talks at conferences. This not only encompasses
highly sophisticated security events like Black Hat or
Troopers. Additionally – on our mission for a safer
world – we try to spread the (security) word at various industry events that are
usually focused on some aspect of the large and ramified IT world, not
necessarily equipped with a strong focus on information security.
A number of such events took place in the last few weeks and here’s some links
on presentations given there. While not being as technically deep as the average
Black Hat or Troopers attendee might expect, we still
hope that one or another valued reader finds them useful (pls note that some
parts are in German).