# Announcing the Web3 SDLC: Secure Development Life Cycle by Philip Gillett

- Channel: [Ethereum Denver](https://streameth.org/ethereum-denver)
- Date: 2023-10-07
- Duration: 18:25
- Watch: https://streameth.org/watch/yt-d5wvO7v5-YA
- YouTube: https://www.youtube.com/watch?v=d5wvO7v5-YA

## Description

Announcing the Web3 SDLC: Secure Development Life Cycle by Philip Gillett 

There is a general lack of security experience in Web3. Currently, the only common security safeguard of Web3 companies are audits, but audits only encompass one small portion of security and at a single point in time. Because auditors are typically the only resource of security knowledge, Web3 companies rely on that knowledge for all of their security needs. While audits are a critical element in securing a protocol, they are a single line of defense, and an expensive one at that.

In this talk, we will present the Web3 SDLC, or Secure Development Life Cycle, a comprehensive security plan that Web3 companies can use to guide every step of their project. We will discuss the four phases of a project (Design, Develop, Deploy, and Defend), providing metrics that can be used to assess the security posture of a project at each phase. This does not obviate the need for an audit, but with security considered and incorporated at each phase of a project's creation, the audit can be targeted at the most technically complex features. Ultimately, incorporating security practices throughout the development process will make protocols more robust and reliable, inspiring more confidence in the protocol and its users, all at a net lower cost overall.

Philip Gillett
Web3 Software Engineer
Arbitrary Execution Inc.
Philip Gillett has experience in blockchain and decentralized technologies, security research, software development, signal processing, and acoustics research. He conducted wind tunnel, water tunnel, and scale model hydroacoustic research for the US Navy for six years before transitioning to computer security research in 2016. He worked as a principal investigator on using commercial-off-the-shelf devices to perform geolocation of wireless transmitters and as a technical lead developing software to live-update wireless firmwares on commercially prevalent devices. Philip has experience with the scientific computing languages MATLAB and LabView, with the general-purpose programming languages Python, JavaScript, Golang, C, ARM assembly, and with the smart contract language Solidity. Philip has a BS and a PhD in Mechanical Engineering from Virginia Tech.

https://twitter.com/echoArbitrary
