EPISODE · May 22, 2017 · 54 MIN
Brook S.E. Schoenfield -- Security in the Design and Architecture
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Fixing vulnerable code is only part of application security; a flawed design can survive every code-level check. Brook S. E. Schoenfield joins Chris and Robert at RSA Conference to explain what security architects do and how they reason about systems before and during implementation. He connects threat modeling to architecture, business priorities, and the practical limits on what a team can change. The discussion explores collaboration between architects and developers, the value of empowering engineering teams, and the communication skills needed to make security advice useful. Brook also reflects on learning from experience and offers a path for people who want to become security architects. The emphasis is on understanding the system and its people well enough to make better design decisions.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Brook S.E. Schoenfield:→ Brook Schoenfield→ Brook Schoenfield on LinkedInMentioned in this episode:→ IEEE Center for Secure Design→ FAIR Institute→ Cyber Kill Chain (Lockheed Martin)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Security in design and architecture with Brook Schoenfield02:41 Brook’s security origin story06:23 Understanding the application security design problem08:24 What a security architect does11:24 Connecting architecture and threats16:59 Turning experience into a better approach26:08 Working within business priorities and constraints33:08 Helping developers and architects collaborate34:01 Organizational structures and shared ownership43:28 Empowering teams with lightweight security practices46:26 Becoming a security architect
Embed this episode
What this episode covers
Fixing vulnerable code is only part of application security; a flawed design can survive every code-level check. Brook S. E. Schoenfield joins Chris and Robert at RSA Conference to explain what security architects do and how they reason about systems before and during implementation. He connects threat modeling to architecture, business priorities, and the practical limits on what a team can change. The discussion explores collaboration between architects and developers, the value of empoweri...
Ready to play
Brook S.E. Schoenfield -- Security in the Design and Architecture
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.