ASW #193 - AppSec (& adjacent) Metrics episode artwork

EPISODE · Apr 19, 2022 · 1H 17M

ASW #193 - AppSec (& adjacent) Metrics

from Application Security Weekly (Audio)

We can create top 10 lists and we can count vulns that we find with scanners and pen tests, but those aren't effective metrics for understanding and improving an appsec program. So, what should we focus on? How do we avoid the trap of focusing on the metrics that are easy to gather and shift to metrics that have clear ways that teams can influence them? In the AppSec News: OAuth tokens compromised, five flaws in a medical robot, lessons from ASN.1 parsing, XSS and bad UX, proactive security & engineering culture at Chime!   Show Notes: https://securityweekly.com/asw193 Segment resources: - https://www.philvenables.com/post/10-fundamental-but-really-hard-security-metrics - https://cloud.google.com/blog/products/devops-sre/using-the-four-keys-to-measure-your-devops-performance   Visit https://www.securityweekly.com/asw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly

Episode metadata supplied by the publisher feed · Published Apr 19, 2022

Embed this episode

NOW PLAYING

ASW #193 - AppSec (& adjacent) Metrics

0:00 1:17:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Application Security Weekly (Audio)?

This episode is 1 hour and 17 minutes long.

When was this Application Security Weekly (Audio) episode published?

This episode was published on April 19, 2022.

Can I download this Application Security Weekly (Audio) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!