Kevin Greene -- Shifting left episode artwork

EPISODE · Jan 19, 2018 · 33 MIN

Kevin Greene -- Shifting left

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Moving a security scanner earlier in the pipeline is not the same as building security into development. Kevin Greene explains what shifting left should mean and why rapid delivery exposes weaknesses in both security strategy and testing tools. Drawing on his work across industry, government research, and MITRE, he argues for capturing practitioners’ experience so teams can apply it repeatedly rather than depend on individual intuition. Chris and Robert explore that idea through threat modeling, architectural decisions, and adversary knowledge. Kevin discusses the Common Architectural Weakness Enumeration, CAPEC, and ATT&CK as ways to connect design choices with realistic failure and attack scenarios. The conversation challenges teams to improve the thinking behind their automation and bring developers usable security knowledge before problems become expensive defects.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Kevin Greene:→ Kevin E. Greene’s websiteMentioned in this episode:→ MITRE CAPEC→ MITRE ATT&CKFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Shifting left with Kevin Greene02:05 Kevin’s security origin story05:43 Security across government and industry07:39 What shifting left should mean11:42 Why DevOps security efforts struggle12:40 Strategy and the limits of testing tools17:04 What it means to codify intuition22:02 Turning experience into threat modeling knowledge24:24 Architectural decisions and CAWE26:55 Using CAPEC and ATT&CK29:00 Bringing adversary knowledge into development

Episode metadata supplied by the publisher feed · Published Jan 19, 2018

Embed this episode

Moving a security scanner earlier in the pipeline is not the same as building security into development. Kevin Greene explains what shifting left should mean and why rapid delivery exposes weaknesses in both security strategy and testing tools. Drawing on his work across industry, government research, and MITRE, he argues for capturing practitioners’ experience so teams can apply it repeatedly rather than depend on individual intuition. Chris and Robert explore that idea through threat modeli...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Kevin Greene -- Shifting left

0:00 33:01

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 33 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 19, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!