EPISODE · Oct 18, 2016 · 31 MIN
Daniel Ramsbrock -- Web Application Pen Testing – Part 1
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What should developers and security teams understand before commissioning a web application penetration test? In part one, Daniel Ramsbrock joins Chris and Robert to establish the purpose, timing, and business value of testing an application from an attacker’s perspective. They compare penetration testing with earlier secure-development activities, explain why developers and testers benefit from working together, and consider how waterfall, agile, and DevOps delivery models change the engagement. Daniel discusses risk-based scoping, testing frequency, business goals, internal versus external testers, and the ethical “hat” terminology used in security. The episode ends by moving from program decisions toward the hands-on testing process continued in part two.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Daniel Ramsbrock:→ Daniel Ramsbrock on LinkedInMentioned in this episode:→ RVAsec→ DEF CON→ Black Hat→ Web Application Penetration Testing — Part 2Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Web application penetration testing, part one01:41 Daniel Ramsbrock’s security origin story03:23 What penetration testing is04:23 Why attackers target applications05:29 The developer perspective on testing06:34 Developers and penetration testers working together07:45 Where penetration testing fits the lifecycle09:19 Why late testing creates problems13:18 Waterfall, agile, and DevOps considerations16:39 How often to run a full penetration test18:41 Using risk to set the testing schedule20:13 Scoping services and applications21:14 Connecting business goals to testing22:12 Building a testing capability24:51 Internal and external testing tradeoffs26:24 White, gray, and black hat terminology30:24 Preparing for the hands-on process
Embed this episode
What this episode covers
What should developers and security teams understand before commissioning a web application penetration test? In part one, Daniel Ramsbrock joins Chris and Robert to establish the purpose, timing, and business value of testing an application from an attacker’s perspective. They compare penetration testing with earlier secure-development activities, explain why developers and testers benefit from working together, and consider how waterfall, agile, and DevOps delivery models change the engagem...
Ready to play
Daniel Ramsbrock -- Web Application Pen Testing – Part 1
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.