EPISODE · Dec 10, 2018 · 32 MIN
Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champions community, and recognizing useful behavior. Chris also describes learning experiences that fit developers’ work and demonstrations that make application risk concrete for leaders. He closes by connecting culture change to observable outcomes, including whether teams resolve security problems more quickly over time.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo:→ Chris Romeo on LinkedInMentioned in this episode:→ OWASP SAMM→ OWASP Juice Shop→ WebGoat→ DevSlopFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Security culture hacking at AppSec USA08:05 Every organization already has a security culture09:53 Transparency and sharing security knowledge10:07 Assessing and measuring the starting point11:39 Turning assessment into an action strategy12:34 Learning developers’ language and methods13:49 Speaking to executives about risk and value14:24 Communication and security’s own assumptions17:37 Building a deliberate security community18:06 Champions programs and learning sessions19:57 Recognition and incentives for useful behavior22:45 Developer-friendly learning and hands-on practice27:43 Educating executives about application security29:04 Demonstrating risk and measuring improvement
Embed this episode
What this episode covers
Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champ...
Ready to play
Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.