Conclusion: All the Pieces You Need for an #AppSec Program episode artwork

EPISODE · Jun 12, 2018 · 29 MIN

Conclusion: All the Pieces You Need for an #AppSec Program

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Which practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development decisions through testing, resilience, and runtime detection. Kevin Greene explains shifting left, Robert Hurlbut defines security champions, Pete Chestna distinguishes SAST, DAST, IAST, and RASP, and Megan Wu describes burnout and its warning signs. Jim Manico presents the OWASP Cheat Sheet Series, David Habusha explains software composition analysis and the Equifax example, and John Melton closes with OWASP AppSensor. Chris and Robert use the clips to show that AppSec is not one tool or one team; it is a connected set of technical practices, community roles, and sustainable working habits.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Chris Romeo and Robert Hurlbut:→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ OWASP Cheat Sheet Series→ OWASP AppSensor→ OWASP Dependency-Check→ National Vulnerability Database→ OWASP Cheat Sheet SeriesFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Building a complete AppSec program00:50 Kevin Greene on shifting left04:58 Robert Hurlbut on security champions06:38 Pete Chestna on SAST, DAST, IAST, and RASP10:16 Megan Wu on recognizing burnout12:50 Jim Manico on the OWASP Cheat Sheet Series17:35 David Habusha on software composition analysis20:45 Could SCA have prevented Equifax?22:44 John Melton on OWASP AppSensor28:05 Closing Season 3

Episode metadata supplied by the publisher feed · Published Jun 12, 2018

Embed this episode

Which practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development decisions through testing, resilience, and runtime detection. Kevin Greene explains shifting left, Robert Hurlbut defines security champions, Pete Chestna distinguishes SAST, DAST, IAST, and RASP, and Megan Wu describes burnout and its warning signs. Jim Manico presents the OWASP Cheat Sheet Series, David Habusha explains software composition anal...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Conclusion: All the Pieces You Need for an #AppSec Program

0:00 29:13

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 29 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 12, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!