Steve Springett -- Software and System Transparency episode artwork

EPISODE · Aug 29, 2024 · 48 MIN

Steve Springett -- Software and System Transparency

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Steve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs. He gives us a rundown of the BOM landscape and unveils some new BOM projects that will continue to unify the security industry. Steve is a seasoned guest of the show so we learn a bit more about Steve's hobbies, providing a personal glimpse into his life outside of technology. Steve Springett educates teams on the strategy and specifics of developing secure software. He practices security at every development lifecycle stage by leading sessions on threat modeling, secure architecture and design, static dynamic component analysis, offensive research, and defensive programming techniques.Today's episode is brought to you by Security Journey.About Security JourneyOur education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.→ Learn more about Security JourneyConnect with Steve Springett:→ CycloneDX→ Software Transparency: Supply Chain Security in an Era of a Software-Driven SocietyMentioned in this episode:→ CycloneDX→ Software Transparency: Supply Chain Security in an Era of a Software-Driven Society→ JC Herz and Steve Springett -- SBOMs and software supply chain assurance→ OWASP Dependency-Track→ CycloneDX→ OWASP Foundation→ Log4j→ Apache Struts→ Open Threat Model (OTM)→ OWASP Threat Dragon Project→ LINDDUN→ PCI Security Standards Council→ Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner→ OWASP Dependency-CheckFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Steve Springett: Software and System Transparency02:04 It's, uh, well, the City of Brotherly Love, isn't that what06:05 That's just, it's just another reminder that we all gotta find07:44 Um, Robert, where are we, where are we going with Steve11:00 And I think a lot of people in AppSec are going12:21 Right14:26 I'd love to get you kind of on the record giving19:08 Based on the Log4j, Log4Shell example, let's have it, let's, let's23:03 We've talked about some of the use cases, but are there24:52 We think about All of these different capabilities and different, I30:18 Let's say in relation to that transparency, but also, uh, commonalities33:19 I know you've been doing some work, Steve, on this idea36:32 I mean, it, it, I think if I, if I kind42:47 Okay. Yeah. So we have 3 questions. Do we, have we45:19 Last question, uh, what's your top book recommendation and why do

Episode metadata supplied by the publisher feed · Published Aug 29, 2024

Embed this episode

Steve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs. He gives us a rundown of the BOM landscape and unveils some new BOM projects that will continue to unify the security industry. Steve is a seasoned guest of the show so we learn a bit more about Steve's hobbies, providing a personal glimpse into his life outside of technology. Steve Springett educates teams on the stra...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Springett -- Software and System Transparency

0:00 48:13

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 29, 2024.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!