Facilitated by Tox B.
Security used to be the last checkbox before release. In a DevSecOps world, it’s baked into every sprint from day one. This session demystifies DevSecOps for Agile practitioners who aren’t engineers but need to understand what “shift-left security” actually means for planning and delivery.
We’ll cover the DevSecOps mindset, how security fits into Definition of Done, common vulnerabilities Agile teams should be aware of at a conceptual level, and how a Scrum Master or Product Owner can help a team build security into their workflow without becoming a bottleneck.
Learning Objectives
Understand what DevSecOps means ad how it differs from bolting security on at the end.
Learn how to incorporate security criteria into Definition of Done and acceptance criteria.
Recognize the vocabulary engineers use around security so you can participate in the conversation.
Identify where security reviews fit naturally into the sprint cadence.
Who Should Attend?
Scrum Masters, Product Owners, and Project/Program Managers working with technical teams, and anyone who wants to be a more effective partner to security and engineering without needing a security background.
Key Takeaways
A shared vocabulary for talking about security with engineering teams.
A checklist for weaving security criteria into planning and Definition of Done.
Confidence to ask the right questions about security readiness before a release.