EPISODE · Nov 29, 2021 · 36 MIN
Ochaun Marshall -- IaC and SAST
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Infrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application. Ochaun Marshall, a developer and application security consultant, explains how that visibility complements static analysis and penetration testing. He discusses where SAST belongs in development, what configuration files can reveal about cloud resources, and why deployed infrastructure still needs monitoring. The conversation covers Terraform, AWS development tools, open-source scanners, and using source access to make a penetration test more productive. Ochaun and Chris then connect those technical practices to developer empathy, explaining why overwhelming engineers with findings undermines trust and how a smaller, carefully tuned set of checks can make security genuinely useful.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Ochaun Marshall:→ Ochaun Marshall on LinkedInMentioned in this episode:→ Semgrep→ Bandit→ TerraformFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Infrastructure as code and SAST with Ochaun Marshall02:35 Returning to cloud application security06:32 Where SAST fits in development07:15 Scanning applications and their infrastructure09:53 Configuration files versus deployed assets12:19 Rebuilding infrastructure instead of changing it manually14:23 Infrastructure programming with the AWS CDK17:19 Using SAST during a penetration test20:26 Open-source tools in the testing toolkit25:06 The security benefits of infrastructure visibility26:55 Tagging resources and monitoring changes29:06 Developer empathy under delivery pressure32:14 Introducing security checks without overwhelming developers
Embed this episode
What this episode covers
Infrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application. Ochaun Marshall, a developer and application security consultant, explains how that visibility complements static analysis and penetration testing. He discusses where SAST belongs in development, what configuration files can reveal about cloud resources, and why deployed infrastructure still needs monitoring. The conversation covers Terraform, AWS...
Ready to play
Ochaun Marshall -- IaC and SAST
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.