Security Control Framework
The developer-security divide: frank talk from both sides

The developer-security divide: frank talk from both sides

8/13/2020 · Brendan O'Leary

What this post added

This post discusses the challenges developers face in adopting security testing tools like SAST and DAST due to high setup barriers and noisy results. It highlights GitLab's approach of integrating security findings into merge requests, allowing developers to validate and address issues early. The security team's role in tuning tools, assessing trends, and providing context is also emphasized. The conversation underscores the need for a shared culture of security and collaboration between development and security teams to effectively find and fix bugs earlier in the development lifecycle.

Read the original post ↗