EPISODE · Mar 9, 2018 · 29 MIN
Chris and Robert -- #AppSec Recommendations
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers. Their list moves from foundational software design and architecture books to secure development, threat modeling, web security, DevOps, checklists, blogs, recorded talks, and local conferences. They discuss learning from Irongeek and YouTube, following practitioners such as Troy Hunt, and using gatherings like BSides, SOURCE, and Black Hat to build relationships as well as technical knowledge. The episode is not a ranked shopping list; it is a guide to assembling a balanced learning practice from books, current writing, hands-on material, video, and community participation.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ Agile Application Security: Enabling Security in a Continuous Delivery Pipeline→ Iron Geek→ The DevOps Handbook→ Threat Modeling: Designing for Security→ The Tangled Web: A Guide to Securing Modern Web Applications→ Start with Why: How Great Leaders Inspire Everyone to Take Action→ Books by Martin Fowler→ Troy Hunt→ Have I Been Pwned→ Google Alerts→ The Checklist Manifesto: How to Get Things Right→ BSides→ Black HatFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Chris and Robert’s AppSec recommendations01:25 Building a balanced learning list02:47 Foundational design and architecture books04:36 Secure development books06:03 Core software security07:35 Irongeek, YouTube, and recorded talks09:25 Threat modeling books12:07 Security blogs and current writing13:58 AppSec conferences15:19 SOURCE, BSides, and Black Hat16:44 Why local conferences matter19:45 Web application security references21:40 Learning from practitioners24:49 The Checklist Manifesto27:01 Community and final recommendations
Embed this episode
What this episode covers
Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers. Their list moves from foundational software design and architecture books to secure development, threat modeling, web security, DevOps, checklists, blogs, recorded talks, and local conferences. They discuss learning from Irongeek and YouTube, following practitioners such as Troy Hunt, and using g...
Ready to play
Chris and Robert -- #AppSec Recommendations
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.