Incorporating Security Best Practices into Agile Teams
Thoughtworks Technology Podcast
Thoughtworks
4.5 • 58 Ratings
🗓️ 1 July 2016
⏱️ 22 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the ThoughtWorks Beacon podcast. |
| 0:04.0 | I'm Johnny LaRoy and I'm here with Chelsea Comlow. |
| 0:07.0 | In this episode, we're discussing security and in particular how that fits into an agile process and into agile delivery teams. |
| 0:15.0 | So it seems like every day we are hearing more and more about security in the headlines. |
| 0:20.0 | And for good reason, businesses |
| 0:22.2 | are the ones to bear the cost if there's a security breach. People are really concerned. |
| 0:26.8 | And, you know, we see this happen every single day. A business might make the headlines, |
| 0:31.8 | and they bear the cost not only financially. There's now starting to be regulations around if there's been a data breach, |
| 0:39.6 | businesses will face fines, but also in the reputation. So, you know, if something were to |
| 0:45.5 | happen with user data, people will think about this and it'll be correlated with that company in the |
| 0:50.2 | future. The damage to brand reputation is really a big risk. Oh, yeah, huge. Yeah, exactly. |
| 0:56.1 | So a year or so ago in our technology radar, we came up with this phrase of the security |
| 1:02.0 | sandwich, which we were seeing as a bit of an anti-pattern, or at least a way to describe |
| 1:06.0 | more traditional security approaches. And we called it the sandwich because the meat of your delivery was in the middle, but then |
| 1:13.6 | security came on either side, like the two pieces of bread. |
| 1:16.6 | There'd be some upfront security planning and documentation, and then some penetration |
| 1:21.3 | testing and certification at the end. |
| 1:23.6 | While that's good and useful and important, most businesses are now moving to much more agile, continuous processes. |
| 1:31.1 | And so we're really on a mission to work out how to bake security processes into continuous delivery approaches. |
| 1:38.5 | And that's really what we want to talk about today. |
| 1:41.6 | And in some ways, there's similar parallels to what we saw in other areas over |
| 1:46.8 | the last decade or so. For example, moving QA, quality assurance and testing into delivery |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from Thoughtworks, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of Thoughtworks and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.
