EPISODE · Feb 10, 2021 · 44 MIN
Jim Routh — Secure software pipelines
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable controls into delivery systems while preserving the speed engineering teams need. From a CISO’s perspective, Jim describes the organizational and funding decisions behind pipeline transformation, the role of threat modeling, and the difference between application security, software security, and broader cyber risk. The discussion focuses on making controls consistent, measuring the value of automation, and structuring teams so secure delivery becomes a shared capability. Jim closes with lessons leaders can use when turning isolated security activities into an enterprise software assurance program.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jim Routh:→ Jim Routh on LinkedInMentioned in this episode:→ Threat Modeling ManifestoFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Building secure software pipelines02:00 Jim Routh’s software security work07:00 From DevSecOps activities to pipeline capabilities13:00 The CISO perspective on software delivery16:00 Embedding security controls in the pipeline27:00 Application security, software security, and cyber risk30:00 Organizational models for secure delivery31:00 Funding a pipeline transformation38:00 Practical takeaways for security leaders43:00 Closing thoughts
Embed this episode
What this episode covers
A secure software pipeline is more than a collection of scanners. Jim Routh joins Chris and Robert to explain how organizations can build repeatable controls into delivery systems while preserving the speed engineering teams need. From a CISO’s perspective, Jim describes the organizational and funding decisions behind pipeline transformation, the role of threat modeling, and the difference between application security, software security, and broader cyber risk. The discussion focuses on makin...
Ready to play
Jim Routh — Secure software pipelines
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.