In the age of ubiquitous internet access and widespread use of smart phone devices, citizens expect that the public sector meets demands of easier, faster and more flexible access to services. This creates also new challenges for public sector information security: Since citizens, patients, tax payers, vehicle user etc. expect to be able to access services in a convenient way online, it is required that data from different sources needs to be integrated and combined, and access to confidential information needs to be highly secure. The challenge is to support this digital transformation without compromising the trust and security of the service consumer.
The underlying software used in this environment needs to be built for a cloud native technology stack and to be secured from the ground up. The software in SaaS scenarios need to be built to be deployed often and consists of micro services which are orchestrated together to provide the end user experience expected by the service consumer (at all public sector levels from local services to national administration). This is where application security builds the foundation to find vulnerabilities early in the software development lifecycle, such as preventing trust boundary violations, checking API security (to secure micro-services interacting with each other), and checking for known vulnerabilities in open source components. All of these checks are needed both in the software supply chain as well as in individual customisations of software products provided by larger vendors. Checkmarx provides solutions for both large vendors as well as for the local customisations developed on top of those products.
Videorecord
The underlying software used in this environment needs to be built for a cloud native technology stack and to be secured from the ground up. The software in SaaS scenarios need to be built to be deployed often and consists of micro services which are orchestrated together to provide the end user experience expected by the service consumer (at all public sector levels from local services to national administration). This is where application security builds the foundation to find vulnerabilities early in the software development lifecycle, such as preventing trust boundary violations, checking API security (to secure micro-services interacting with each other), and checking for known vulnerabilities in open source components. All of these checks are needed both in the software supply chain as well as in individual customisations of software products provided by larger vendors. Checkmarx provides solutions for both large vendors as well as for the local customisations developed on top of those products.
Videorecord
Sign in to Autumn ITAPA 2024
Carsten Huth
Carsten has over 15 years of experience in InfoSec and over 10 years of experience in application security. He has carried out numerous AppSec program rollouts and deployments as a professional services consultant becoming a practice principal and managing a team of software security consultants across Europe. When joining Checkmarx in 2016, Carsten initially worked as the first Technical Account Manager (TAM), managing the largest accounts of Checkmarx in EMEA. Shortly after joining Checkmarx, Carsten started building the team of technical account managers around him and a year later also a team of AppSec advisors. Carsten has contributed to the OWASP OpenSAMM standard and has presented at various application security conferences.
See more info about the speaker