Matt Clapham -- Development Security Maturity episode artwork

EPISODE · Oct 11, 2016 · 48 MIN

Matt Clapham -- Development Security Maturity

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Can you learn enough about a development team’s security practices in an hour to give it useful direction? Matt Clapham joins Chris and Robert to explain his lightweight approach to estimating development security maturity through five key behaviors. They discuss preparing for the assessment, learning from defect records and existing artifacts, and holding a conversation that encourages honest answers rather than anxiety about being graded. Matt walks through scoring practices such as threat modeling and vulnerability response, then explains how the results can guide improvement. The discussion also examines the experience an assessor needs, the model’s limitations, and its relationship to broader approaches such as BSIMM and SAMM. The goal is an actionable view of how a team actually works.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Clapham:→ Matt Clapham on LinkedInMentioned in this episode:→ RSA slides: Estimating Development Security Maturity in About an Hour→ BSIMM→ OWASP SAMMFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Estimating development security maturity with Matt Clapham01:32 Matt’s product security background03:15 What development security maturity means05:15 Why measurement can make developers anxious08:20 Why a maturity assessment is useful11:03 Preparing for the assessment16:33 Understanding the application before the meeting19:49 What defect records reveal about a team21:10 Running the development-team conversation22:30 Communication that encourages useful answers26:38 Scoring security behaviors29:54 Evaluating threat modeling practices34:39 Vulnerability response as a maturity signal37:52 Can a team outgrow the model?42:12 Limitations and advantages of the approach45:30 How the model relates to BSIMM and SAMM

Episode metadata supplied by the publisher feed · Published Oct 11, 2016

Embed this episode

Can you learn enough about a development team’s security practices in an hour to give it useful direction? Matt Clapham joins Chris and Robert to explain his lightweight approach to estimating development security maturity through five key behaviors. They discuss preparing for the assessment, learning from defect records and existing artifacts, and holding a conversation that encourages honest answers rather than anxiety about being graded. Matt walks through scoring practices such as threat ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Matt Clapham -- Development Security Maturity

0:00 48:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 11, 2016.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!