
Building an Engineering Security Culture - Failure stories included - Edwin Kwan, Tyro Payments
Cloud Security Podcast
00:00
The Book That Fails in DevSecOps
The book that failed in DevSecOps is called Epic Failures in DevSec Ops. It's a collection of stories from people who tried to do things right but they were a fail. The approach was based on trap modeling, where you test your code and it verifies certain things. So we had one way of doing database logging with the same kind of intersystem offsides. And then we ran well, people were losing support. People are just going to security shit because all day, it's not looking at us and going, this is terrible.
Transcript
Play full episode