Product security is undergoing a rapid process of formalization, driven an uptick in legislation and standardization. As a result, we’ll be able to communicate more clearly on security concerns, and products can be expected to become more secure overall. Well-established practices, such as those shared by several OWASP projects have existed for years but are now reaching a broader audience because they provide practical structure in an increasingly regulated environment. This talk explores how regulation, standards, and community-driven best practices converge, and how shared knowledge can help organizations collectively raise the baseline of product security rather than treating compliance as an isolated exercise.
