Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10 episode artwork

EPISODE · Sep 25, 2017 · 35 MIN

Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use? Andrew van der Stock and Brian Glas discuss the governance and research behind the project’s next release during a contentious revision cycle. They explain how public comments affect decisions, why a large share of contributed data came from one source, and how the team planned to compare findings across applications. The conversation covers scoring, release candidates, the familiar one-page format, and connections to ASVS, Proactive Controls, and the Web Security Testing Guide. Chris presses them on what the list should become in the future and how listeners can participate. The result is a candid view of maintaining a widely influential community standard.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Andrew van der Stock and Brian Glas:→ Andrew van der Stock on LinkedIn→ Brian Glas on LinkedIn→ OWASP Top 10Mentioned in this episode:→ OWASP Top 10→ OWASP ASVS→ OWASP Proactive Controls→ OWASP Web Security Testing Guide→ OWASP ESAPIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The future of the OWASP Top 1002:21 Andrew van der Stock’s security origin story05:30 Experience maintaining the project06:36 Governance and decision-making08:13 How public comments affect the release10:57 Data concentration in the first candidate13:15 Comparing findings across applications16:07 Scoring and understanding impact19:30 The origins of ASVS21:22 Connecting the Top 10 to other OWASP projects23:06 The release-candidate schedule26:21 Preserving the one-page format28:58 What the Top 10 should become33:16 How listeners can participate34:26 Final thoughts

Episode metadata supplied by the publisher feed · Published Sep 25, 2017

Embed this episode

How should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use? Andrew van der Stock and Brian Glas discuss the governance and research behind the project’s next release during a contentious revision cycle. They explain how public comments affect decisions, why a large share of contributed data came from one source, and how the team planned to compare findings across applications. The conversation covers scoring, release candidates, the fam...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10

0:00 35:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 25, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!