Chris and Robert -- Security in the Methodology episode artwork

EPISODE · Sep 26, 2016 · 27 MIN

Chris and Robert -- Security in the Methodology

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one. Waterfall makes phase gates, documentation, and specialized reviews visible, but often delays feedback. Agile breaks work into smaller increments, uses user stories and acceptance criteria, and creates opportunities to test security continuously. The hosts discuss stand-ups, sprints, continuous integration, threat modeling, abuse cases, reusable requirements, and the difficulty of defining “done” when security work spans multiple stories. Their conclusion is not that one methodology automatically produces secure software. Security succeeds when its activities fit the team’s real delivery process and provide useful feedback at the moment decisions are made.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ Agile Manifesto→ Microsoft SDLFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Security in development methodologies02:33 Why organizations still use Waterfall04:07 Documentation and predictable phase gates06:01 Where Waterfall came from07:19 Applying security to each Waterfall phase08:40 Moving from Waterfall to Agile10:25 Testing inside every sprint12:09 User stories and acceptance criteria13:25 Stand-ups, retrospectives, and feedback15:00 Continuous integration and Agile16:49 What it means for a story to be done18:19 Fitting AppSec into Agile work20:32 Turning security needs into stories21:50 Testing authorization requirements24:25 Threat modeling and abuse cases27:21 Final methodology lessons

Episode metadata supplied by the publisher feed · Published Sep 26, 2016

Embed this episode

How should application security change when a team moves from Waterfall to Agile? Chris and Robert compare the two development models and map security work onto each one. Waterfall makes phase gates, documentation, and specialized reviews visible, but often delays feedback. Agile breaks work into smaller increments, uses user stories and acceptance criteria, and creates opportunities to test security continuously. The hosts discuss stand-ups, sprints, continuous integration, threat modeling, ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris and Robert -- Security in the Methodology

0:00 27:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 27 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 26, 2016.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!