EPISODE · Oct 11, 2016 · 48 MIN
Matt Clapham -- Development Security Maturity
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Can you learn enough about a development team’s security practices in an hour to give it useful direction? Matt Clapham joins Chris and Robert to explain his lightweight approach to estimating development security maturity through five key behaviors. They discuss preparing for the assessment, learning from defect records and existing artifacts, and holding a conversation that encourages honest answers rather than anxiety about being graded. Matt walks through scoring practices such as threat modeling and vulnerability response, then explains how the results can guide improvement. The discussion also examines the experience an assessor needs, the model’s limitations, and its relationship to broader approaches such as BSIMM and SAMM. The goal is an actionable view of how a team actually works.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Clapham:→ Matt Clapham on LinkedInMentioned in this episode:→ RSA slides: Estimating Development Security Maturity in About an Hour→ BSIMM→ OWASP SAMMFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Estimating development security maturity with Matt Clapham01:32 Matt’s product security background03:15 What development security maturity means05:15 Why measurement can make developers anxious08:20 Why a maturity assessment is useful11:03 Preparing for the assessment16:33 Understanding the application before the meeting19:49 What defect records reveal about a team21:10 Running the development-team conversation22:30 Communication that encourages useful answers26:38 Scoring security behaviors29:54 Evaluating threat modeling practices34:39 Vulnerability response as a maturity signal37:52 Can a team outgrow the model?42:12 Limitations and advantages of the approach45:30 How the model relates to BSIMM and SAMM
Embed this episode
What this episode covers
Can you learn enough about a development team’s security practices in an hour to give it useful direction? Matt Clapham joins Chris and Robert to explain his lightweight approach to estimating development security maturity through five key behaviors. They discuss preparing for the assessment, learning from defect records and existing artifacts, and holding a conversation that encourages honest answers rather than anxiety about being graded. Matt walks through scoring practices such as threat ...
Ready to play
Matt Clapham -- Development Security Maturity
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.