EPISODE · Jul 4, 2017 · 36 MIN
Jim Manico -- MORE OWASP!
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How can developers turn OWASP’s many projects into practical help with the code they write? Jim Manico joins Chris and Robert to discuss the resources he helps build and the problems each is meant to solve. He traces his move from software development into security education, then explains the OWASP Java Encoder and how its focused approach differs from a larger security library such as ESAPI. The conversation also explores the debate surrounding the 2017 OWASP Top 10, the value of the Cheat Sheet Series, and the developer-oriented Proactive Controls. Jim shares lessons from writing Iron-Clad Java and from teaching application security. Throughout, he emphasizes accessible guidance, sound security APIs, and community work that helps developers put defenses into practice.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jim Manico:→ Jim Manico on LinkedIn→ Manicode SecurityMentioned in this episode:→ OWASP Java Encoder Project→ OWASP ESAPI→ OWASP Cheat Sheet Series→ OWASP Proactive ControlsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 OWASP projects with Jim Manico01:01 From software development to security education02:27 Learning security as a developer05:12 Joining and contributing to OWASP10:32 The OWASP Java Encoder11:56 Java Encoder compared with ESAPI13:24 Bringing safer APIs into the platform20:00 The debate around the OWASP Top 1024:16 Collaboration at the OWASP Summit25:33 How to use the Cheat Sheet Series28:10 Proactive Controls for developers29:25 Writing Iron-Clad Java31:55 Life, teaching, and opportunities in AppSec
Embed this episode
What this episode covers
How can developers turn OWASP’s many projects into practical help with the code they write? Jim Manico joins Chris and Robert to discuss the resources he helps build and the problems each is meant to solve. He traces his move from software development into security education, then explains the OWASP Java Encoder and how its focused approach differs from a larger security library such as ESAPI. The conversation also explores the debate surrounding the 2017 OWASP Top 10, the value of the Cheat ...
Ready to play
Jim Manico -- MORE OWASP!
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.