EPISODE · Jun 12, 2018 · 29 MIN
Conclusion: All the Pieces You Need for an #AppSec Program
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Which practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development decisions through testing, resilience, and runtime detection. Kevin Greene explains shifting left, Robert Hurlbut defines security champions, Pete Chestna distinguishes SAST, DAST, IAST, and RASP, and Megan Wu describes burnout and its warning signs. Jim Manico presents the OWASP Cheat Sheet Series, David Habusha explains software composition analysis and the Equifax example, and John Melton closes with OWASP AppSensor. Chris and Robert use the clips to show that AppSec is not one tool or one team; it is a connected set of technical practices, community roles, and sustainable working habits.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Cheat Sheet Series→ OWASP AppSensor→ OWASP Dependency-Check→ National Vulnerability Database→ OWASP Cheat Sheet SeriesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Building a complete AppSec program00:50 Kevin Greene on shifting left04:58 Robert Hurlbut on security champions06:38 Pete Chestna on SAST, DAST, IAST, and RASP10:16 Megan Wu on recognizing burnout12:50 Jim Manico on the OWASP Cheat Sheet Series17:35 David Habusha on software composition analysis20:45 Could SCA have prevented Equifax?22:44 John Melton on OWASP AppSensor28:05 Closing Season 3
Embed this episode
What this episode covers
Which practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development decisions through testing, resilience, and runtime detection. Kevin Greene explains shifting left, Robert Hurlbut defines security champions, Pete Chestna distinguishes SAST, DAST, IAST, and RASP, and Megan Wu describes burnout and its warning signs. Jim Manico presents the OWASP Cheat Sheet Series, David Habusha explains software composition anal...
Ready to play
Conclusion: All the Pieces You Need for an #AppSec Program
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.