Pete Chestna -- SAST, DAST, and IAST. Oh My! episode artwork

EPISODE · Feb 16, 2018 · 35 MIN

Pete Chestna -- SAST, DAST, and IAST. Oh My!

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Buying more scanners does not automatically create a better application security program. Pete Chestna explains SAST, DAST, IAST, runtime protection, and composition analysis, then connects those technologies to the developers who must use their results. Starting from a listener’s question about false positives, he explores speed, accuracy, workflow integration, and the difference between a real flaw and an accepted risk. Pete offers a gradual approach for a new program: understand the application inventory, establish a baseline, train developers, and improve one weakness category at a time. For more mature teams, he discusses combining metrics, preventing new vulnerabilities, and retaining human testing where tools fall short. His central argument is that effective programs develop secure developers, with secure software following from that capability.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Pete Chestna:→ Pete Chestna on LinkedInMentioned in this episode:→ Veracode→ BrakemanFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Making sense of AppSec testing tools00:47 Pete’s security origin story03:01 SAST, DAST, IAST, RASP, and SCA explained07:25 Tool maturity and deployment models09:08 Developer concerns: speed, accuracy, and integration12:51 Compensating controls and risk decisions14:18 Security knowledge and developer motivation16:37 Starting a new AppSec program18:05 Baseline measurement before enforcement20:34 Improving one weakness category at a time23:46 Preventing new vulnerabilities25:06 The goal is secure developers26:43 Combining data in a mature program28:43 Where penetration testing still adds value31:18 Open-source testing tools and tradeoffs

Episode metadata supplied by the publisher feed · Published Feb 16, 2018

Embed this episode

Buying more scanners does not automatically create a better application security program. Pete Chestna explains SAST, DAST, IAST, runtime protection, and composition analysis, then connects those technologies to the developers who must use their results. Starting from a listener’s question about false positives, he explores speed, accuracy, workflow integration, and the difference between a real flaw and an accepted risk. Pete offers a gradual approach for a new program: understand the applic...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Pete Chestna -- SAST, DAST, and IAST. Oh My!

0:00 35:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 16, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!