From the course: Introduction to Product Security

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Managing risk in product security

Managing risk in product security

- [Narrator] Risk management is such a broad corporate term, but we do it every day. Putting on our seat belts before we start our car. We do this for a few reasons. We don't want to get a ticket, we don't want to become injured in a car wreck, or it's just second nature at this point. Managing risk for a product is not unlike managing risk in our personal lives or other areas of information security. What sets product security apart is the parties involved. Collaboration with developers, engineers, legal, and sometimes customers is required to continuously manage security risk to the company products. Sure, we can dump the information into a Jira ticket and cross our fingers that it lands in the hands of a developer that cares, but this is not an effective approach. Communicating risk requires buy-in and buy-in requires preparation. There are three ways to get buy-in when you're looking to build a risk management process to improve the security of a product. Align to business…

Contents