Chris and Robert -- The Activities of the Secure Development Lifecycle episode artwork

EPISODE · Sep 20, 2016 · 44 MIN

Chris and Robert -- The Activities of the Secure Development Lifecycle

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Which activities turn a secure development lifecycle from an aspiration into repeatable work? Chris and Robert walk through security requirements, authentication and authorization, threat modeling, coding standards, approved libraries, code review, static analysis, dependency management, dynamic scanning, penetration testing, and post-release response. For each activity, they explain who benefits, when it belongs in development, and what it can reveal that another control cannot. The conversation emphasizes shared ownership: architects, developers, testers, operations, and response teams each see different parts of the risk. Tools support the process but do not replace design judgment or human testing. The episode provides a practical map of the SDL and shows how its activities connect from initial requirements through production feedback.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Top 10→ OWASP ESAPI→ Microsoft Safe C Library→ PSIRT Services Framework (FIRST.org)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Activities of a secure development lifecycle01:45 Security requirements03:27 Authentication and authorization05:24 Capturing requirements in development work07:17 Threat modeling09:12 Identifying threats systematically12:14 How threat models help testers14:09 Secure coding standards15:52 Why developers need actionable guidance17:44 Approved frameworks and cryptography20:49 Code review and static analysis23:53 Owning third-party dependency risk25:18 Software composition analysis26:53 Triage and false positives29:38 Testing within the delivery process31:26 Dynamic application security testing33:07 Network versus application scanning35:23 Comparing multiple tools37:35 Why penetration testing still matters40:45 Product security incident response43:37 Secure software as a connected system

Episode metadata supplied by the publisher feed · Published Sep 20, 2016

Embed this episode

Which activities turn a secure development lifecycle from an aspiration into repeatable work? Chris and Robert walk through security requirements, authentication and authorization, threat modeling, coding standards, approved libraries, code review, static analysis, dependency management, dynamic scanning, penetration testing, and post-release response. For each activity, they explain who benefits, when it belongs in development, and what it can reveal that another control cannot. The conversa...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris and Robert -- The Activities of the Secure Development Lifecycle

0:00 44:07

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 44 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 20, 2016.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!