Hi [[ session.user.profile.firstName ]]

Building a Culture of Secure Programming in your Organisation

We all know that fixing defects early in the SDLC is the right approach to building secure software. Security needs to be in every part of the pipeline but it’s often hard to get everybody onboard with software security initiatives.

Come join us on this webinar to explore how to build a culture of proactive secure programming in your technical organization and how to implement security as an enabler without disrupting the velocity of projects in modern development teams. See how Synopsys tools and services can allow you to build secure, reliable and quality software.
Recorded Feb 20 2019 70 mins
Your place is confirmed,
we'll send you email reminders
Presented by
Amanvir Sangha, Consultant, Synopsys
Presentation preview: Building a Culture of Secure Programming in your Organisation
  • Channel
  • Channel profile
  • Time is Money - Interactive Application Security Testing at DevOps Speed Aug 19 2021 4:00 pm UTC 39 mins
    Scott Tolley, Application Security Specialist, Synopsys and Amit Sharma, Application Security Evangelist, Synopsys
    Would you like to find out more about Interactive Application Security Testing (IAST), a new category of AppSec born in the age of DevOps?

    Join Scott Tolley & Amit Sharma (Application Security Specialists) as they discuss how to bridge the gap from DevOps to DevSecOps, without slowing everything down.

    Agenda:
    Application Security trends and challenges in moving from DevOps to DevSecOps
    Introducing IAST and Seeker
    Product Demonstration
    Q&A - come prepared with your questions and we’ll answer live on the webinar.
  • Financial Services Study Shows Why Investing in AppSec Matters Jun 17 2021 3:00 pm UTC 34 mins
    Drew Kilbourne and Larry Ponemon
    If you’re a provider of financial services, then client trust, privacy, and risk management are critical to your success. Therefore, you must protect your organization’s sensitive data from cyber attacks and data breaches. A recent survey of current software security practices in the financial services industry explores the industry’s software security posture and its ability to address security-related issues.

    In this webinar with Drew Kilbourne, managing director, Synopsys and Larry Ponemon, chairman, Ponemon Institute, will review findings from the report and discuss what they mean for the industry at large. Here’s a preview of some key findings:

    - 56% of organizations had experienced an attack resulting in system failure and downtime.
    - 74% were concerned about security vulnerabilities introduced by third-party suppliers, but less than 43% said they require third parties to adhere to cyber security requirements.
    - Only 34% of financial applications are tested for vulnerabilities, and only 25% of respondents were confident in their ability to detect vulnerabilities before going to market.
  • The Evolution of IAST: Building Security Into Testing Jun 10 2021 4:00 pm UTC 56 mins
    Featuring Sandy Carielli, Principal Analyst, Forrester & Kimm Yeo, Product Marketing Manager, Synopsys
    Interactive application security testing (IAST) is evolving quickly to become a key DevSecOps tool used to build continuous application security into today’s modern but increasingly complex software ecosystem.

    There’s a growing demand for and shift toward complex composite-based apps, but they involve multiple dev teams as well as new technologies such as microservices, serverless, containers, and mixed deployment approaches (cloud, containers). How do you secure your web, cloud, and microservices applications? How do you balance the speed, quality, and innovation that your customers demanding today?

    Join this live Synopsys webinar to learn why organizations are looking into alternative dynamic security testing solutions, and why next-generation tools such as IAST are here to stay. In this webinar, learn about:

    •Trends in the latest Forrester IAST survey data
    •Developments in continuous testing, test automation, and DevSecOps
    •The role of IAST in testing and reporting

    Don’t miss this informative webinar. Register today.
  • Integrate AppSec Tools Into DevOps Pipelines Without Slowing Down May 26 2021 5:00 pm UTC 60 mins
    Jason Schmitt, GM of Software Integrity Group at Synopsys and Dan Kennedy, Research Director at 451 Research
    Integrating security testing into continuous integration / continuous delivery or deployment (CI/CD) pipelines requires integrating tool scans for static application security testing (SAST), dynamic application security testing (DAST), or software composition analysis (SCA), which are each performed at different stages of the CI/CD pipeline. These tools each have their own strengths and weaknesses and are complementary to each other. But how long each tool takes to complete a scan affects how often and when they are deployed into a staging or production environment.

    A recent paper by 451 Research shows that production web applications are expected to be largely free of security defects, and the pressures of keeping up with release cycles that deploy more frequently have compelled information security and development teams to better collaborate. Synopsys addresses those challenges with Intelligent Orchestration.

    In this webinar, you’ll learn:

    Why legacy CI/CD approaches can’t keep up with the speed of DevOps
    How Synopsys Intelligent Orchestration:
    - Helps break down silos and leverages a dedicated pipeline that automatically runs the right security tools at the right time
    - Triggers manual testing activities based on software development life cycle events and predefined policies, while also providing continuous metrics and feedback
    - Enables security teams to automate security gates and enforce policies for all applications across their organization, at enterprise scale
  • Is IAST the Next Big Thing in AppSec? May 20 2021 4:00 pm UTC 60 mins
    Kimm Yeo & Eugene Pakhomov, Synopsys
    Interactive application security testing (IAST) provides distinct advantages over traditional application security testing methods. No matter where you are in your AppSec maturity and test readiness model, you can benefit from real-time vulnerability testing in running applications. If you don’t already have an IAST or dynamic application security testing strategy, now is the time to make one.

    Join us for this live Synopsys webinar to learn why security and development teams are relying on IAST tools to fill the gap between static (SAST) and dynamic testing (DAST). We’ll cover:

    • What IAST is and why you should care
    • How IAST has quickly evolved to speed up modern application security testing
    • How to test and secure new technologies including microservices and serverless computing
    • Where IAST fits into your SDLC
    • What to look for in an IAST tool

    Don’t miss this informative webinar. Register today.
  • Why Design Quality Matters in Software Due Diligence May 19 2021 4:00 pm UTC 60 mins
    Ashwin Ala, Professional Services Consultant & Phil Odence, GM, Black Duck Audits at Synopsys
    Design quality audits are often overlooked in software due diligence, but understanding the overall health of a company’s software system is vital to reducing technical debt. Acquiring poorly designed or coded software, can have long term impacts on the viability of the software.

    Join this live Synopsys webinar to learn why having a complete picture of code structure will impact future development. We’ll cover:

    • The importance of design quality
    • Factors to assess during software due diligence
    • Benefits of a design quality audit

    Don’t miss this informative webinar. Register today.
  • Part 4: Automate the Initiation and Management of Out-of-Band AppSec Activities May 5 2021 12:00 pm UTC 45 mins
    Meera Rao, Senior Director - Product Management (DevOps Solutions)
    The final part in the webinar series provides real-world guidance on how to balance application security activities, including both those that are automated and run inline in your CI/CD pipelines, and the out-of-band activities that are traditionally executed manually. Implementing security gates at strategic places in the CI/CD pipeline to break the build when critical and high vulnerabilities are found keeps teams informed and reduces communication overhead. Just as there must be continuous integration, continuous delivery, and continuous deployment, there also must be continuous collaboration, and continuous communication across development, security, and operations teams.
  • Open Source Risk in M&A by the Numbers Apr 28 2021 4:00 pm UTC 60 mins
    Phil Odence, GM, Black Duck Audits at Synopsys
    In over 1,500 codebases audited in 2020, Black Duck Audits found that nearly every one contained open source components. Not only that, but a significant percentage of “proprietary code” overall was open source. However, left unmanaged, open source can lead to license compliance issues plus security and code quality risks. Whether you’re on the buy side or sell side, these risks could negatively affect valuation in an M&A transaction.

    Many acquirers have come to understand all this in concept; the Black Duck Audit Services group has the data. Join us for this webinar as we answer questions about the code of tech companies being acquired today. We’ll cover:

    • Open source license and security risks by the numbers
    • Why audits have become the norm in M&A tech due diligence
    • How you can get a complete picture of open source risks

    Don’t miss this informative webinar. Register today.
  • 2021 OSSRA Report: Open Source Trends, Risks & Management Apr 21 2021 4:00 pm UTC 60 mins
    Tim Mackey, Principal Security Strategist, Synopsys
    The 2021 Open Source Security and Risk Analysis report (OSSRA) looks at the state of open source use in over 1,250 distinct applications created by organizations in 17 industries. The use of open source continues to grow and businesses of all sizes are now powered by open source software. If left unmanaged, open source may introduce security, quality, and license compliance risks. Are you ready to take control of your open source?

    Join us for this live Synopsys webinar to get a look at our 2021 report results and learn how teams can use the data to inform their overall open source governance plans. We’ll cover:

    • Why open source governance matters
    • The latest trends in open source usage
    • Open source management strategies

    Don’t miss this informative webinar. Register today.
  • Shifting Left to Accelerate Security Approvals for ATOs in Defense Programs Apr 20 2021 5:00 pm UTC 56 mins
    Joe Jarzombek, Director for Government & Critical Infrastructure Programs
    Demands for more secure software and more rapid application development have led to the emergence of risk-based DevSecOps, which adds security activities, increases depth, and improves testing governance. The best strategy is to shift from a reactive to a proactive security approach that injects security at the right time and place with automated continuous testing. Arming developers with proven application security tools integrated within their supporting CI/CD toolchains reduces the time and effort needed to achieve authorization for changes in software to operate on a DOD network or weapon system. Key technologies such as static application security testing (SAST) and software composition analysis (SCA) help developers deliver high-quality and more secure codebases in the front end of the pipeline. Mitigating technical debt early in the software development life cycle (SDLC) provides significant cost savings while accelerating the delivery of more secure software.

    Join Joe Jarzombek (USAF Lt. Col., retired) as he discusses means for successfully scaling responsiveness with a secure SDLC. He will cover how:

    •Automated continuous testing can be used throughout the SDLC
    •Catching security defects at the desktop can be like using a spell-checker to drive savings while rapidly mitigating risks attributable to exploitable software
    •Developer productivity can provide more time for creating new features rather than fixing newly entered issues

    Don’t miss this informative webinar. Register today
  • Lunch and Learn Part 3: Reduce the Burden on Developers With Automation Recorded: Apr 15 2021 53 mins
    Meera Rao, Senior Director - Product Management (DevOps Solutions)
    Developers are often taught to emphasize functionality over security, and many developers aren’t security experts. For this reason, it’s crucial to ensure they stay aware of the risks of vulnerable code. But training materials are often static and inconvenient to access, using the internet for guidance isn’t consistent or reliable, and remediation advice from tools isn’t necessarily project-aware or product-specific. And unfortunately, security experts are often seen as an impediment to business goals, and they may not be experienced developers. The third part of the webinar series covers developer enablement and avoiding defect management overload.
  • Make the most of AppSec with OWASP guidelines and SAST Solutions Recorded: Apr 14 2021 60 mins
    Balaji Bhardwaj, Senior Sales Engineer
    OWASP guidelines are one of the most popular and effective security frameworks. This webinar explores the effectiveness of the OWASP framework and how the entire application development team can make the best use of these guidelines. It also details the practices that should be incorporated in the day-to-day activities of application development teams to ensure the biggest impact on the security program.
  • DevSecOps Practices and Open Source Management Recorded: Apr 13 2021 58 mins
    Tim Mackey, Principal Security Strategist for CyRC
    The Synopsys Cybersecurity Research Center (CyRC), in partnership with Censuswide, an international market research consultancy, conducted a survey of 1,500 IT professionals to analyze the tools and processes organizations are employing to integrate open source management into their DevOps practices. The findings highlight some of the challenges organizations face as the pressure for velocity, while building secure, high-quality applications forces DevOps teams to integrate and automate tools and processes effectively.

    Join Tim Mackey, principal security strategist for CyRC, as he examines the findings from the survey and provides recommendations for teams looking to optimize open source management in their DevOps environment. Topics include:

    · The maturity of DevOps adoption and its core challenges
    · The core tools being adopted by teams and how best to use them and when
    · How open source policies are being adopted, enforced, and managed
    · Key strategies for mitigating open source security risk without impacting software delivery schedules
  • Testing security of micro-services, APIs and cloud-native apps Recorded: Apr 8 2021 52 mins
    Ainsley Braun, Product Director, Synopsys and John Salomon, Director Continental Europe, Middle East, & Africa FS-ISAC
    How are you security testing APIs, web services, and cloud-native applications? Are you able to test application security without impacting efficiency? Do you have sufficient visibility into sensitive data that your applications handle?

    This session we will be joined by guest speaker John Salomon from FS-ISAC where we discuss ways of ensuring that your security testing is developer friendly, and that your insight into application vulnerabilities and remediation guidance meet your organization’s risk appetite. We will go over ways of ensuring fast, relevant contextual training, and efficient remediation of detected vulnerabilities.
  • What You Need to Know about Software Due Diligence Recorded: Mar 24 2021 61 mins
    Phil Odence, GM Black Duck Audits, Synopsys
    There’s risk in any M&A transaction but having the right software due diligence approach can help mitigate that risk. If software is a large part of the deal, understanding the legal, security, code and design quality risks in the target’s codebase is key. Do you know the right questions to ask?

    Join this live Synopsys webinar to create or tweak your due diligence playbook. We’ll cover:

    •Understanding the software due diligence landscape
    •The risks to look out for (and why)
    •What questions to ask in the process
    •How to choose the right audit partner

    Don’t miss this informative webinar. Register today!
  • Part 2: Common Challenges of Operationalizing Integration Recorded: Mar 24 2021 52 mins
    Meera Rao, Senior Director - Product Management (DevOps Solutions)
    In this second part of the webinar series, learn how to build security tools into a continuous integration/continuous delivery pipeline. Topics covered include:
    • How can you ensure that release cycles are not slowed down?
    • How should you manage false positives?
    • How do you satisfy compliance needs?
  • Why SAST and SCA Together Are Better, Faster, Stronger Recorded: Mar 18 2021 42 mins
    Utsav Sanghani, Senior Product Manager, Staff, Synopsys
    Static application security testing (SAST) is critical for uncovering and eliminating issues in proprietary code. However, over 60% of the code in an average application today is composed of open source components. SAST isn’t designed to find open source vulnerabilities (CVEs) or identify open source licenses. And manually maintaining a repository of approved open source components for developers is inefficient and time consuming. That’s where software composition analysis (SCA) comes in.

    Join a Synopsys expert as he explores the benefits of bringing SAST and SCA together. He’ll explain why using an SCA tool to scan open source dependencies is as imperative to a software development strategy as using SAST to test proprietary code. He’ll also demonstrate how developers, by combining SAST and SCA analysis in the IDE, can address issues holistically as they code, saving time and increasing productivity so they can deliver secure, high-quality software faster.
  • Improve your security posture with IAST Recorded: Mar 18 2021 58 mins
    Vishwas Sharma, Senior Sales Engineer, Synopsys
    Application security testing has become more prevalent, leading to the need for more effective tools in the software development life cycle (SDLC). SAST, DAST, and penetration testing (pen testing) usually works well in legacy software development environments. However, with the emergence of new technologies and practices such as containers, microservices, and DevOps, these traditional tools struggle to keep up with the fast pace of modern application delivery.

    Join us as we discuss the benefits of Synopsys award winning Seeker IAST and how it fits into DevSecOps:

    • Complements IAST with SAST and DAST methods by enabling IDE and CI/CD integration making it a true DevsecOps solution.
    • How IAST helps the pen-testing, or pre-production teams to perform one final test before they can sign off the application for end use.
    • How IAST enables the security teams to secure your web apps before they are at risk of costly data breaches
  • Why SAST and SCA Together Are Better, Faster, Stronger Recorded: Mar 18 2021 42 mins
    Utsav Sanghani, Senior Product Manager, Staff, Synopsys
    Static application security testing (SAST) is critical for uncovering and eliminating issues in proprietary code. However, over 60% of the code in an average application today is composed of open source components. SAST isn’t designed to find open source vulnerabilities (CVEs) or identify open source licenses. And manually maintaining a repository of approved open source components for developers is inefficient and time consuming. That’s where software composition analysis (SCA) comes in.

    Join a Synopsys expert as he explores the benefits of bringing SAST and SCA together. He’ll explain why using an SCA tool to scan open source dependencies is as imperative to a software development strategy as using SAST to test proprietary code. He’ll also demonstrate how developers, by combining SAST and SCA analysis in the IDE, can address issues holistically as they code, saving time and increasing productivity so they can deliver secure, high-quality software faster.
  • The Changing Dynamics of AppSec, and Key Lessons You Can Learn Recorded: Mar 10 2021 63 mins
    Ian Hall, Head of Client Services, APAC, Synopsys
    AppSec is continually evolving as new technologies come to the fore. Just as Cloud has now become ubiquitous, orchestration for containers is also taking hold. How you secure those technologies is important as is who is responsible for leading those efforts and the tools they leverage to do that.

    In this panel discussion, we will identify and analyse some key recent trends in AppSec as well as the emerging activities that organizations are doing to protect themselves and their data.
Build secure, high-quality software faster.
Synopsys helps development teams build secure, high-quality software, minimizing risks while maximizing speed and productivity. With a combination of industry-leading tools, services, and expertise, only Synopsys helps organizations optimize security and quality in DevSecOps and throughout the software development life cycle.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Building a Culture of Secure Programming in your Organisation
  • Live at: Feb 20 2019 11:00 am
  • Presented by: Amanvir Sangha, Consultant, Synopsys
  • From:
Your email has been sent.
or close