My slides are now available for you to revisit (if you would like a copy for yourself, email me), here at SlideShare.net
Most of you already know how much I love to stand in front of fresh set of faces to deliver the message of web application security. Every once in a while I get the rare pleasure of venturing out of my element (the "security" audience) and talking to an audience that doesn't actually have any vested interest in security... yet. This past couple of days spent with QA engineers and software testers at StarEast has been absolutely priceless. I can't tell you how much joy it brings me to see the light bulbs go on as you slowly make the transition to knowing and understanding what should make you lose sleep - that security is everyone's problem.
The audiences that came out to the "Hacking Flash" talk, as well as the "Building Practical Test Cases..." talk were wonderfully interactive and really game me faith in the fact that the message is reading more and more of the right folks. I know I mentioned at least a few times that the QA teams are the key to security's success, and I'll further explain for everyone else why that's the case in a later post - but know it's absolutely, 100%, no-bs truth.
When you get back to your jobs stop by your security team's desks and tell them that you are the secret step in a successful security strategy and program. Take a snapshot of their reaction. Remember, there is generall a 10:1 ration of QA to security staff... and your effectiveness is measured in the depth of cooperation with your security teams in decreasing your enterprise's risk on the web.
Given all that, I want to post some follow-up stories. I would like to get some brave souls to reply to me (either privately or here as a comment) with how you've taken this information back to your organization and utilized it for the company's greater good. What kinds of reactions have you gotten? Please let me know and I would love to have you guest-blog either semi-anonymously, or identifying yourself if you'd like!
Thanks again! Good luck out there.
Posted
05-07-2009 6:22 PM
by
RafalLos