EPISODE · Sep 20, 2016 · 44 MIN
Chris and Robert -- The Activities of the Secure Development Lifecycle
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Which activities turn a secure development lifecycle from an aspiration into repeatable work? Chris and Robert walk through security requirements, authentication and authorization, threat modeling, coding standards, approved libraries, code review, static analysis, dependency management, dynamic scanning, penetration testing, and post-release response. For each activity, they explain who benefits, when it belongs in development, and what it can reveal that another control cannot. The conversation emphasizes shared ownership: architects, developers, testers, operations, and response teams each see different parts of the risk. Tools support the process but do not replace design judgment or human testing. The episode provides a practical map of the SDL and shows how its activities connect from initial requirements through production feedback.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Top 10→ OWASP ESAPI→ Microsoft Safe C Library→ PSIRT Services Framework (FIRST.org)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Activities of a secure development lifecycle01:45 Security requirements03:27 Authentication and authorization05:24 Capturing requirements in development work07:17 Threat modeling09:12 Identifying threats systematically12:14 How threat models help testers14:09 Secure coding standards15:52 Why developers need actionable guidance17:44 Approved frameworks and cryptography20:49 Code review and static analysis23:53 Owning third-party dependency risk25:18 Software composition analysis26:53 Triage and false positives29:38 Testing within the delivery process31:26 Dynamic application security testing33:07 Network versus application scanning35:23 Comparing multiple tools37:35 Why penetration testing still matters40:45 Product security incident response43:37 Secure software as a connected system
Embed this episode
What this episode covers
Which activities turn a secure development lifecycle from an aspiration into repeatable work? Chris and Robert walk through security requirements, authentication and authorization, threat modeling, coding standards, approved libraries, code review, static analysis, dependency management, dynamic scanning, penetration testing, and post-release response. For each activity, they explain who benefits, when it belongs in development, and what it can reveal that another control cannot. The conversa...
Ready to play
Chris and Robert -- The Activities of the Secure Development Lifecycle
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.