EPISODE · Jun 19, 2017 · 39 MIN
Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Static analysis can help developers find security flaws early, but buying a scanner does not create an effective program. Mark Willis joins Chris and Robert to explain how he fits testing into the software development lifecycle and works with developers to make results useful. They discuss choosing tools for the actual codebase, tuning recurring false positives, and evaluating products before committing to them. The conversation weighs scan coverage against the pace of DevOps and considers when dynamic testing and a deeper penetration test are appropriate. Mark also describes finding developers who want to become security champions and helping them build their skills. The recurring theme is collaboration: useful testing depends on context, timely feedback, and respect for the people fixing the code.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mark Willis:→ Mark Willis at RSA ConferenceMentioned in this episode:→ OWASP→ OWASP Testing GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Static analysis and developer collaboration with Mark Willis01:12 Mark’s journey from development into security07:19 Empathy for the people writing the code10:42 Placing static analysis in the SDLC14:23 Tuning tools and reducing false positives16:27 Evaluating scanners before buying19:20 Static analysis at DevOps speed23:02 What dynamic scanners can and cannot do28:05 Working within the testing and release window31:13 Choosing applications for deeper penetration testing33:43 Helping developers move into security36:51 Learning with the OWASP Testing Guide
Embed this episode
What this episode covers
Static analysis can help developers find security flaws early, but buying a scanner does not create an effective program. Mark Willis joins Chris and Robert to explain how he fits testing into the software development lifecycle and works with developers to make results useful. They discuss choosing tools for the actual codebase, tuning recurring false positives, and evaluating products before committing to them. The conversation weighs scan coverage against the pace of DevOps and considers wh...
Ready to play
Mark Willis -- I Just Like Static Analysis. Static Analysis is My Favorite
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.