EPISODE · Feb 16, 2018 · 35 MIN
Pete Chestna -- SAST, DAST, and IAST. Oh My!
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Buying more scanners does not automatically create a better application security program. Pete Chestna explains SAST, DAST, IAST, runtime protection, and composition analysis, then connects those technologies to the developers who must use their results. Starting from a listener’s question about false positives, he explores speed, accuracy, workflow integration, and the difference between a real flaw and an accepted risk. Pete offers a gradual approach for a new program: understand the application inventory, establish a baseline, train developers, and improve one weakness category at a time. For more mature teams, he discusses combining metrics, preventing new vulnerabilities, and retaining human testing where tools fall short. His central argument is that effective programs develop secure developers, with secure software following from that capability.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Pete Chestna:→ Pete Chestna on LinkedInMentioned in this episode:→ Veracode→ BrakemanFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Making sense of AppSec testing tools00:47 Pete’s security origin story03:01 SAST, DAST, IAST, RASP, and SCA explained07:25 Tool maturity and deployment models09:08 Developer concerns: speed, accuracy, and integration12:51 Compensating controls and risk decisions14:18 Security knowledge and developer motivation16:37 Starting a new AppSec program18:05 Baseline measurement before enforcement20:34 Improving one weakness category at a time23:46 Preventing new vulnerabilities25:06 The goal is secure developers26:43 Combining data in a mature program28:43 Where penetration testing still adds value31:18 Open-source testing tools and tradeoffs
Embed this episode
What this episode covers
Buying more scanners does not automatically create a better application security program. Pete Chestna explains SAST, DAST, IAST, runtime protection, and composition analysis, then connects those technologies to the developers who must use their results. Starting from a listener’s question about false positives, he explores speed, accuracy, workflow integration, and the difference between a real flaw and an accepted risk. Pete offers a gradual approach for a new program: understand the applic...
Ready to play
Pete Chestna -- SAST, DAST, and IAST. Oh My!
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.