EPISODE · Sep 15, 2019 · 44 MIN
Brook Schoenfield — Security is a messy problem
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why doesn't an executive mandate and a scanning tool add up to a software security program? Brook Schoenfield joins Chris and Robert to unpack security as a human, technical, and organizational problem that crosses the whole development lifecycle. He describes the limits of policy and testing, then explains how noisy tools lose developer trust. His practical alternative is to begin with high-confidence checks developers can use themselves, supported by deeper specialist testing rather than an impossible promise to find everything. The conversation turns to culture hacking: sharing responsibility, helping teams work through the consequences of their own incidents, and using threat modeling to make security tangible. Brook closes by connecting those habits to iterative improvement and the security of the delivery pipeline itself.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Brook S.E. Schoenfield:→ LinkedIn→ Brook's websiteMentioned in this episode:→ Securing Systems: Applied Security Architecture and Threat Models→ IOActiveFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction05:03 Why a mandate is not a security program08:32 The appeal and limits of simple answers09:50 Security crosses every domain11:41 Getting engineers to want security16:59 Why security tools lose developer trust24:10 Layering developer checks and specialist testing25:55 Putting useful tools in developers' hands29:15 Fast feedback while writing code33:00 The program-building lessons so far34:43 Culture hacking and shared responsibility40:25 Continuous improvement and delivery-chain security43:33 What's next in Brook's writing
Embed this episode
What this episode covers
Why doesn't an executive mandate and a scanning tool add up to a software security program? Brook Schoenfield joins Chris and Robert to unpack security as a human, technical, and organizational problem that crosses the whole development lifecycle. He describes the limits of policy and testing, then explains how noisy tools lose developer trust. His practical alternative is to begin with high-confidence checks developers can use themselves, supported by deeper specialist testing rather than an...
Ready to play
Brook Schoenfield — Security is a messy problem
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.