EPISODE · Jul 25, 2017 · 43 MIN
Dave Ferguson -- The OWASP Top 10 Proactive Controls
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Developers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them? Dave Ferguson joins the podcast to walk through the OWASP Top 10 Proactive Controls as they stood at the time of this recording. The discussion covers early security testing, parameterized queries, output encoding, input validation, authentication, access control, data protection, logging, security frameworks, and error handling. Dave connects the controls to familiar application risks and explains how OWASP cheat sheets provide the implementation detail behind the high-level guidance. Chris and Dave also debate where intrusion detection belongs and why security features should be reusable. The result is a developer-focused conversation about turning awareness of common failures into concrete engineering practices.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Dave Ferguson:→ Dave Ferguson on LinkedInMentioned in this episode:→ OWASP Proactive Controls→ OWASP Cheat Sheet Series→ OWASP Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Proactive security controls with Dave Ferguson07:40 A developer-focused security baseline08:40 Verify security early and often12:34 Parameterize queries15:01 Encode data for its output context18:14 Validate all inputs23:07 Identity, authentication, and session management25:25 Implement access controls29:03 Protect data at rest and in transit32:18 Logging and intrusion detection36:32 Use security frameworks and libraries38:33 Handle errors and exceptions securely41:18 Turning vulnerability awareness into action
Embed this episode
What this episode covers
Developers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them? Dave Ferguson joins the podcast to walk through the OWASP Top 10 Proactive Controls as they stood at the time of this recording. The discussion covers early security testing, parameterized queries, output encoding, input validation, authentication, access control, data protection, logging, security frameworks, and error handling. Dave connects the controls to familiar app...
Ready to play
Dave Ferguson -- The OWASP Top 10 Proactive Controls
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.