Amazon Web Services
In this AWS re:Inforce 2023 session, Maria and Gerald from Cuscal discuss rethinking the 'Sec' in DevSecOps for modern architectures. They explore how Cuscal, a major payment provider in Australia, has implemented DevSecOps practices to deliver secure and compliant financial services with small teams. The presentation covers cultural challenges, security of the pipeline, security in the pipeline, and supply chain risk. Key topics include transitioning to a product-centric approach, implementing mono-repo strategies, shifting security left, automating deployments, and managing vulnerabilities. The speakers share insights on using AWS services and third-party tools to enhance security and efficiency in cloud-native and hybrid environments.