James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed episode artwork

EPISODE · Sep 24, 2021 · 54 MIN

James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E. Schoenfield join Chris and Robert to discuss their book Building in Security at Agile Speed and the organizational work behind sustainable software security. They explain why practitioners need enough technical fluency to collaborate with developers, how leaders can recognize when a program is becoming self-sufficient, and which behaviors reveal that security has spread beyond a central team. The conversation returns repeatedly to people, trust, incentives, and measurement. It closes by challenging assumptions about penetration testing and showing how continuous delivery requires security practices that evolve with the development system rather than sit outside it.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with James Ransome and Brook S. E. Schoenfield:→ James Ransome on LinkedIn→ Brook Schoenfield on LinkedInMentioned in this episode:→ Building in Security at Agile Speed→ Core Software SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Building security at agile speed02:49 James Ransome’s security origin story05:11 The book and the problem it addresses08:08 Why this book and why now15:59 Technical fluency for security leaders21:36 When a security program becomes self-sufficient24:48 Organic adoption and signs of maturity30:36 Behaviors leaders can measure34:19 People, process, and tools37:07 Building trust across the organization46:58 Penetration testing in continuous delivery50:12 Final lessons from the authors

Episode metadata supplied by the publisher feed · Published Sep 24, 2021

Embed this episode

Why do application security programs stall even after teams buy tools and define processes? James Ransome and Brook S. E. Schoenfield join Chris and Robert to discuss their book Building in Security at Agile Speed and the organizational work behind sustainable software security. They explain why practitioners need enough technical fluency to collaborate with developers, how leaders can recognize when a program is becoming self-sufficient, and which behaviors reveal that security has spread be...

Distinct summary based on available episode metadata or transcript content.

Ready to play

James Ransome and Brook Schoenfield -- trust and verify: Building in Security at Agile Speed

0:00 54:19

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 54 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 24, 2021.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!