Ochaun Marshall -- IaC and SAST episode artwork

EPISODE · Nov 29, 2021 · 36 MIN

Ochaun Marshall -- IaC and SAST

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Infrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application. Ochaun Marshall, a developer and application security consultant, explains how that visibility complements static analysis and penetration testing. He discusses where SAST belongs in development, what configuration files can reveal about cloud resources, and why deployed infrastructure still needs monitoring. The conversation covers Terraform, AWS development tools, open-source scanners, and using source access to make a penetration test more productive. Ochaun and Chris then connect those technical practices to developer empathy, explaining why overwhelming engineers with findings undermines trust and how a smaller, carefully tuned set of checks can make security genuinely useful.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ochaun Marshall:→ Ochaun Marshall on LinkedInMentioned in this episode:→ Semgrep→ Bandit→ TerraformFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Infrastructure as code and SAST with Ochaun Marshall02:35 Returning to cloud application security06:32 Where SAST fits in development07:15 Scanning applications and their infrastructure09:53 Configuration files versus deployed assets12:19 Rebuilding infrastructure instead of changing it manually14:23 Infrastructure programming with the AWS CDK17:19 Using SAST during a penetration test20:26 Open-source tools in the testing toolkit25:06 The security benefits of infrastructure visibility26:55 Tagging resources and monitoring changes29:06 Developer empathy under delivery pressure32:14 Introducing security checks without overwhelming developers

Episode metadata supplied by the publisher feed · Published Nov 29, 2021

Embed this episode

Infrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application. Ochaun Marshall, a developer and application security consultant, explains how that visibility complements static analysis and penetration testing. He discusses where SAST belongs in development, what configuration files can reveal about cloud resources, and why deployed infrastructure still needs monitoring. The conversation covers Terraform, AWS...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Ochaun Marshall -- IaC and SAST

0:00 36:29

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 29, 2021.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!