3 ms·
Sounds like someone is tired of getting dinged for using outdated security practices in their application designs. I came from the other side of things. I know
by surge 3y ago
Sounds like someone is tired of getting dinged for using outdated security practices in their application designs.
I came from the other side of things. I know what its like, but the fact they care more about features and not fixing vulnerabilities or designing applications to have good security is a failing on their end. Shift left, do it early, so we're not finding it right when the product is getting ready to ship when its finally in a form ready to review.
>3. Build standardized patterns.
Yeah, you can have them, but then the various project teams don't follow them or even look at them during the design. Then wonder why its being reported later. Are they kept accountable when they don't follow the prescribed patterns and it causes project delays when its called out? No. It's our fault for road blocking.
>4. Abandon the perimeter model.
Uh yeah, we talk about zero trust but its the app teams saying "its an internal application, not publicly accessible so its not a big deal if there's no encryption or credentials are stored in the clear" in their arguments to why its not an issue or they shouldn't have to fix it.
>5. Advise, don’t dictate.
I can not speak for every place, but we recommend solutions and call them "Recommendations" but if there's another better solution to reducing the risk we're not the SME's in your product, as long as it adequately remediates the issues through some sort of control, detection, or fix, it's not really for us to say how its done.
>6. Ask platform teams to integrate security.
They're not interested, they're interested in copying and pasting code from past applications with the same old/bad practices. They even bring practices into new platforms that have great solutions for managing a risk (such as credential storage) and do it the old way (keep creds in a config file that ships with the artifact).
Cybersecurity isn't special, but its the developers (not all) IME that treat it like it is and not part of their job responsibilities.