Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo episode artwork

EPISODE · Dec 10, 2018 · 32 MIN

Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champions community, and recognizing useful behavior. Chris also describes learning experiences that fit developers’ work and demonstrations that make application risk concrete for leaders. He closes by connecting culture change to observable outcomes, including whether teams resolve security problems more quickly over time.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo:→ Chris Romeo on LinkedInMentioned in this episode:→ OWASP SAMM→ OWASP Juice Shop→ WebGoat→ DevSlopFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Security culture hacking at AppSec USA08:05 Every organization already has a security culture09:53 Transparency and sharing security knowledge10:07 Assessing and measuring the starting point11:39 Turning assessment into an action strategy12:34 Learning developers’ language and methods13:49 Speaking to executives about risk and value14:24 Communication and security’s own assumptions17:37 Building a deliberate security community18:06 Champions programs and learning sessions19:57 Recognition and incentives for useful behavior22:45 Developer-friendly learning and hands-on practice27:43 Educating executives about application security29:04 Demonstrating risk and measuring improvement

Episode metadata supplied by the publisher feed · Published Dec 10, 2018

Embed this episode

Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo

0:00 32:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 32 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on December 10, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!