David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React episode artwork

EPISODE · Dec 16, 2019 · 30 MIN

David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Where should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react. Drawing on his background in software testing, he maps the pillars to requirements and design, coding and testing, and deployment and feedback. These are parallel areas to develop, not three stages to finish in order. David explains how relationships with security champions make prevention possible, how testing expertise strengthens detection, and why external findings can make risk tangible for developers. The conversation also explores bug bounties, feedback loops, and meaningful recognition. His emphasis is on building a supportive security culture through partnerships and small, useful controls rather than overwhelming teams with a complete program at once.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with David Kosorok:→ LinkedInMentioned in this episode:→ OWASP Triangle→ SSL Labs Server Test→ Hacker101→ HackerOne→ BugcrowdFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:33 From software testing to application security03:56 What testers bring to security07:07 Quality and security share a purpose08:39 Prevent, detect, and react09:56 Prevention through requirements and design12:46 Partnerships and security champions16:24 Detection during coding and testing18:59 Working with quality engineers20:36 Reacting to risk in deployed applications23:49 Making external findings useful feedback28:42 Recognition that encourages participation

Episode metadata supplied by the publisher feed · Published Dec 16, 2019

Embed this episode

Where should a small application security team begin when it cannot do everything? David Kosorok joins Chris and Robert with a practical framework: prevent, detect, and react. Drawing on his background in software testing, he maps the pillars to requirements and design, coding and testing, and deployment and feedback. These are parallel areas to develop, not three stages to finish in order. David explains how relationships with security champions make prevention possible, how testing expertis...

Distinct summary based on available episode metadata or transcript content.

Ready to play

David Kosorok — The Three Pillars of an AppSec Program: Prevent, Detect, and React

0:00 30:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 30 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on December 16, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!