EPISODE · Aug 28, 2018 · 21 MIN
Matt Tesauro -- #AppSec Pipeline as Toolbox
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How can a small AppSec team make sense of thousands of applications and a growing pile of security work? Matt Tesauro explains the AppSec Pipeline project as a toolbox for organizing and automating the work, rather than a single prescribed product. He describes the pressure that led him and Aaron Weaver to map intake, triage, testing, and delivery, then connect tools around those stages. The conversation examines DefectDojo’s role in tracking findings and effort, baseline testing across applications, and the value of reusable containers. Matt also explains how teams can adapt the pieces to their own development practices and where to begin. The result is a practical view of automation that supports decisions about both technical risk and limited team capacity.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Matt Tesauro:→ Matt Tesauro on LinkedIn→ OWASP AppSec Pipeline projectMentioned in this episode:→ OWASP DefectDojo→ OWASP Dependency-Check→ ZAP→ BanditFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The AppSec Pipeline toolbox with Matt Tesauro00:59 Matt’s security origin story02:34 Discovering the OWASP community04:31 Why the AppSec Pipeline project began05:58 Scaling a small security team with automation07:11 Tools that fit into the pipeline08:59 Tracking work and resource tradeoffs10:31 DefectDojo’s place in the process12:18 Baseline testing across an application portfolio14:14 A toolbox teams can adapt15:30 Getting started: intake, triage, testing, and delivery18:43 OWASP and sharing practical experience
Embed this episode
What this episode covers
How can a small AppSec team make sense of thousands of applications and a growing pile of security work? Matt Tesauro explains the AppSec Pipeline project as a toolbox for organizing and automating the work, rather than a single prescribed product. He describes the pressure that led him and Aaron Weaver to map intake, triage, testing, and delivery, then connect tools around those stages. The conversation examines DefectDojo’s role in tracking findings and effort, baseline testing across appli...
Ready to play
Matt Tesauro -- #AppSec Pipeline as Toolbox
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.