EPISODE · Mar 16, 2018 · 42 MIN
Jim Routh -- Selling #AppSec Up The Chain
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What if the strongest argument for funding application security is better software delivery rather than fear of a breach? Jim Routh draws on building five software security programs to explain how he makes the case to executives. He connects security with quality, productivity, and the cost of fixing defects, then distinguishes the language that works with business leaders from the conversations practitioners have about risk. Chris and Robert ask how to put that case into practice, build developer participation, and use security champions to extend a program’s reach. Jim also explores board attention, industry crises, and the choices that determine whether a program scales. The conversation offers a leader’s perspective on earning investment by making secure development part of how the business succeeds.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jim Routh:→ Jim Routh on LinkedInMentioned in this episode:→ BSIMM→ Meltdown and SpectreFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Making the executive case for AppSec01:41 Jim’s route into security leadership03:54 The state of enterprise software security07:46 Connecting security with quality and productivity08:27 How Jim wins funding for security programs16:39 When to talk about risk21:37 Turning the business case into a program25:31 Software security and executive attention29:40 Using industry crises to drive improvement35:23 Why security champions help programs scale36:17 The next challenges for software security
Embed this episode
What this episode covers
What if the strongest argument for funding application security is better software delivery rather than fear of a breach? Jim Routh draws on building five software security programs to explain how he makes the case to executives. He connects security with quality, productivity, and the cost of fixing defects, then distinguishes the language that works with business leaders from the conversations practitioners have about risk. Chris and Robert ask how to put that case into practice, build deve...
Ready to play
Jim Routh -- Selling #AppSec Up The Chain
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.