From Pentest to DevSecOps: Lessons from Building an Open Source AppSec Program with DefectDojo, DependencyTrack and OWASP PTRS
How can an organisation effectively develop an application security program using open-source tools and community-driven standards? How can we move from isolated security reports to continuous application security management?
During the workshop, we will present our practical experience in building an Application Security (AppSec) program at one of the largest technical universities in Poland, based exclusively on open-source solutions. Through concrete examples, we will demonstrate the use of DefectDojo as a central vulnerability management platform, DependencyTrack for monitoring software supply chain risks, and OWASP PTRS (Penetration Testing Reporting Standard) for creating consistent and structured security reports.
The workshop will focus on practical challenges, solution architecture, and lessons learned from implementing an AppSec program in the environment of a large public-sector organisation.
The workshop is intended for information security professionals, IT teams, DevOps and SOC teams, as well as anyone interested in implementing practical and scalable application security management models in public-sector organisations.