DEF CON 32 - Transforming AppSec  Protecting 'Everything as Code' - Kunal Bhattacharya

DEF CON 32 - Transforming AppSec Protecting 'Everything as Code' - Kunal Bhattacharya

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 45:00

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

In an "everything is code" world, application security faces challenges from role blurring, data overload, and shifting responsibilities, demanding context-driven, balanced practices rather than over-reliance on developers or automation.

Key Takeaways:
• Role blurring in CI/CD pipelines undermines ownership and context; clear separation between developers, security, and operations is fading 5:56.
• Data explosion in vulnerability management requires better architecture and correlation, not just more tools 6:32.
• Developers should not bear all security burdens—shifting left too much creates bottlenecks and overloads 13:35–14:00.
• Contextual, role-specific training for developers is more effective than generic security education 15:52–16:29.
• Unified vulnerability management is possible only through data unification, not tool or policy unification—remediation must account for asset-specific risk and effort 25:54–29:10.
• AI can assist with patching and PR generation but should not enable auto-remediation without solid foundational practices in asset and policy management 35:02–37:35.

Security must evolve with context, not just tools—developers are not the root problem, but education and organizational structure need improvement.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hi uh my name is Kunal bachara I a senior security leader and adviser um my security Journey has been pretty long before I came into security I've done a bunch of different things uh was a developer was s adman was QA uh architect uh finally moved to security and never looked back um I also have had the privilege of building a homegrown bug boundi program before the likes of hacker one I don't know if they are the spons answer uh but U uh and then eventually moved into a lot of the security stuff and I just considered myself to be a u lifelong learner uh apart from security uh I guess I'm a average Runner swimmer um Dad whatever um yeah so that's me Sarah you want to introduce yourself hi everyone my name is Sarah har I lead vulnerability management at docy sign I in in the vulnerability m…