This talk is about real world security requirements and practices. It discusses that security requirements often come from pentests rather than user needs, and that companies typically have separate development, operations, and security teams working on projects rather than products. It advocates having one view of all applications and services across their lifecycles. The talk presents practices for organizing security collaboratively and continuously across teams, including building security into the development pipeline, operating secure environments, and managing security ongoing.