EPISODE · Dec 16, 2019 · 30 MIN
David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Where should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react. Drawing on his background in software testing, he maps the pillars to requirements and design, coding and testing, and deployment and feedback. These are parallel areas to develop, not three stages to finish in order. David explains how relationships with security champions make prevention possible, how testing expertise strengthens detection, and why external findings can make risk tangible for developers. The conversation also explores bug bounties, feedback loops, and meaningful recognition. His emphasis is on building a supportive security culture through partnerships and small, useful controls rather than overwhelming teams with a complete program at once.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with David Kosorok:→ LinkedInMentioned in this episode:→ OWASP Triangle→ SSL Labs Server Test→ Hacker101→ HackerOne→ BugcrowdFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:33 From software testing to application security03:56 What testers bring to security07:07 Quality and security share a purpose08:39 Prevent, detect, and react09:56 Prevention through requirements and design12:46 Partnerships and security champions16:24 Detection during coding and testing18:59 Working with quality engineers20:36 Reacting to risk in deployed applications23:49 Making external findings useful feedback28:42 Recognition that encourages participation
Embed this episode
What this episode covers
Where should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react. Drawing on his background in software testing, he maps the pillars to requirements and design, coding and testing, and deployment and feedback. These are parallel areas to develop, not three stages to finish in order. David explains how relationships with security champions make prevention possible, how testing expertis...
Ready to play
David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.