Matt Tesauro -- #AppSec Pipeline as Toolbox episode artwork

EPISODE · Aug 28, 2018 · 21 MIN

Matt Tesauro -- #AppSec Pipeline as Toolbox

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How can a small AppSec team make sense of thousands of applications and a growing pile of security work? Matt Tesauro explains the AppSec Pipeline project as a toolbox for organizing and automating the work, rather than a single prescribed product. He describes the pressure that led him and Aaron Weaver to map intake, triage, testing, and delivery, then connect tools around those stages. The conversation examines DefectDojo’s role in tracking findings and effort, baseline testing across applications, and the value of reusable containers. Matt also explains how teams can adapt the pieces to their own development practices and where to begin. The result is a practical view of automation that supports decisions about both technical risk and limited team capacity.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Tesauro:→ Matt Tesauro on LinkedIn→ OWASP AppSec Pipeline projectMentioned in this episode:→ OWASP DefectDojo→ OWASP Dependency-Check→ ZAP→ BanditFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The AppSec Pipeline toolbox with Matt Tesauro00:59 Matt’s security origin story02:34 Discovering the OWASP community04:31 Why the AppSec Pipeline project began05:58 Scaling a small security team with automation07:11 Tools that fit into the pipeline08:59 Tracking work and resource tradeoffs10:31 DefectDojo’s place in the process12:18 Baseline testing across an application portfolio14:14 A toolbox teams can adapt15:30 Getting started: intake, triage, testing, and delivery18:43 OWASP and sharing practical experience

Episode metadata supplied by the publisher feed · Published Aug 28, 2018

Embed this episode

How can a small AppSec team make sense of thousands of applications and a growing pile of security work? Matt Tesauro explains the AppSec Pipeline project as a toolbox for organizing and automating the work, rather than a single prescribed product. He describes the pressure that led him and Aaron Weaver to map intake, triage, testing, and delivery, then connect tools around those stages. The conversation examines DefectDojo’s role in tracking findings and effort, baseline testing across appli...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Matt Tesauro -- #AppSec Pipeline as Toolbox

0:00 21:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 21 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 28, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!