As software organizations try to bring security earlier in the development processes, what can or should regular software or operations engineers know about security? Taking as given that we want them to build secure systems, that demands a shared understanding of the security issues that might come up, and agreement on what that body of knowledge might entail. Without this knowledge, they'll keep building insecure systems...
By: Adam Shostack
Full Abstract & Presentation Materials: https://www.blackhat.com/us-22/briefi...