Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite episode artwork

EPISODE · Jun 19, 2017 · 39 MIN

Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Static analysis can help developers find security flaws early, but buying a scanner does not create an effective program. Mark Willis joins Chris and Robert to explain how he fits testing into the software development lifecycle and works with developers to make results useful. They discuss choosing tools for the actual codebase, tuning recurring false positives, and evaluating products before committing to them. The conversation weighs scan coverage against the pace of DevOps and considers when dynamic testing and a deeper penetration test are appropriate. Mark also describes finding developers who want to become security champions and helping them build their skills. The recurring theme is collaboration: useful testing depends on context, timely feedback, and respect for the people fixing the code.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mark Willis:→ Mark Willis at RSA ConferenceMentioned in this episode:→ OWASP→ OWASP Testing GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Static analysis and developer collaboration with Mark Willis01:12 Mark’s journey from development into security07:19 Empathy for the people writing the code10:42 Placing static analysis in the SDLC14:23 Tuning tools and reducing false positives16:27 Evaluating scanners before buying19:20 Static analysis at DevOps speed23:02 What dynamic scanners can and cannot do28:05 Working within the testing and release window31:13 Choosing applications for deeper penetration testing33:43 Helping developers move into security36:51 Learning with the OWASP Testing Guide

Episode metadata supplied by the publisher feed · Published Jun 19, 2017

Embed this episode

Static analysis can help developers find security flaws early, but buying a scanner does not create an effective program. Mark Willis joins Chris and Robert to explain how he fits testing into the software development lifecycle and works with developers to make results useful. They discuss choosing tools for the actual codebase, tuning recurring false positives, and evaluating products before committing to them. The conversation weighs scan coverage against the pace of DevOps and considers wh...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite

0:00 39:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 39 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 19, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!