The presentation discusses the importance of scaling application security through education and defines application security as product security. It also highlights the ISO IEC 25010 system and software quality model and the impact of technical debt on quality.
- Application security is a crucial aspect of cybersecurity that involves building secure software systems.
- ISO IEC 25010 system and software quality model prioritizes security as an intrinsic quality system.
- Technical debt can lead to a drop in non-functional qualities, including security.
- Scaling application security through education is essential to ensure developers are equipped with the necessary skills to identify and address security issues during code review.
If a change negatively impacts performance, it would be immediately visible to customers, but if it negatively impacts security, it might never be noticed. Hope is not a strategy when it comes to security.