Loading…
Wednesday November 4, 2026 9:00am - 5:00pm PST
How to streamline the identification of security requirements associated with software functionalities in agile methodologies using OWASP Cornucopia to plan and manage application security from analysis and design, and also manage security defects associated with unimplemented or poorly implemented controls.

1. Introduction: Understand the theory about evil user stories modeling, when to execute in the SDLC and the value of the exercise.
2. Understand the importance of integrating security requirements from the user story definition phase.
3.- Identify how to integrate security requirements into user stories and convert them into actionable tasks within the backlog using Evil User Stories modeling (a variation of Abuse Case Modeling in Agile combined with secure scrum).
4.- Design a single product backlog that integrates security functionalities and controls into user stories avoiding the creation of a cybersecurity parallel backlog.
5.- Apply a proactive approach where security is part of the design process, not just the final validation.
6.- Designing a traceability matrix based on the execution of OWASP Cornucopia
Speakers
avatar for Max Alejandro Gomez Sanchez Vergaray

Max Alejandro Gomez Sanchez Vergaray

AppSec & DevSecOps Consultant | Risk-driven Security for real-world products | S-SDLC, DevSecOps, Secure Design & Threat Modeling Trainer, AppSec & DevSecOps Consultant | Risk-driven Security for real-world products | S-SDLC, DevSecOps, Secure Design & Threat Modeling Trainer

I designed and led the application security program during the digital transformation process of one of the largest banks in Latin America, training more than 3,000 people in secure software development, specially in Secure Design using OWASP Cornucopia, another tools for threat modeling... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link