Farshad Abasi -- Three Models for Deploying AppSec Resources episode artwork

EPISODE · Jul 9, 2023 · 9 MIN

Farshad Abasi -- Three Models for Deploying AppSec Resources

from The Application Security Podcast · host Chris Romeo

Application security teams rarely have enough specialists to embed one expert with every development team. Farshad Abasi joins Chris for a focused comparison of three staffing models he used while building enterprise AppSec programs: expert-led support, a federated risk-based model, and a security champion or deputy model. Farshad explains why dedicated experts struggle to scale, how application tiering concentrates attention on the systems that matter most, and how champions can take ownership of routine security work with coaching and escalation from AppSec. The episode offers a practical progression for organizations trying to expand coverage without pretending scarce specialists can attend every stand-up and review every user story.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Farshad Abasi:→ Farshad Abasi on LinkedIn→ Forward SecurityMentioned in this episode:→ OWASP Security Champions Guide→ Forward SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Three models for deploying AppSec resources01:21 Farshad Abasi’s path from development to security03:28 The expert-led AppSec model05:45 A federated, risk-based model07:31 The security champion or deputy model08:41 Choosing a model that can scale

Episode metadata supplied by the publisher feed · Published Jul 9, 2023

Embed this episode

Application security teams rarely have enough specialists to embed one expert with every development team. Farshad Abasi joins Chris for a focused comparison of three staffing models he used while building enterprise AppSec programs: expert-led support, a federated risk-based model, and a security champion or deputy model. Farshad explains why dedicated experts struggle to scale, how application tiering concentrates attention on the systems that matter most, and how champions can take ownersh...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Farshad Abasi -- Three Models for Deploying AppSec Resources

0:00 9:18

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 9 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 9, 2023.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!