EPISODE · Jul 15, 2021 · 1H 11M
Thinking back, Looking forward - A Balanced Approach to Securing our Software Future
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Software security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now. Drawing on work at Parasoft and across government and industry, Kevin discusses secure development practices, standards, developer enablement, and the limits of relying on tools alone. The conversation connects supply-chain failures and the federal cybersecurity executive order to cyber resilience, penetration testing, red teams, and assurance. It closes by looking ahead to policy, software minimalism, and the changes organizations must make if they want secure software to become a repeatable engineering outcome rather than a late-stage scramble.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Kevin Greene:→ Parasoft→ Kevin Greene on API security testingMentioned in this episode:→ Parasoft→ OWASP Proactive Controls→ MITRE ATT&CK→ Threat Modeling Manifesto→ Executive Order 14028→ Apache StrutsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Looking back at software security02:03 Kevin Greene’s path through AppSec04:54 What a balanced security approach means06:59 Prevention, detection, and response09:52 Standards and repeatable engineering practices12:38 Making secure development easier15:42 Helping developers own security18:40 The current state of software assurance22:36 Guidance, governance, and accountability24:46 Where security tools help—and where they do not28:00 Supply-chain failures and SolarWinds30:00 Why old software problems persist33:00 The federal cybersecurity executive order37:00 Adapting to rapid change40:00 Building cyber resilience42:00 The role of penetration testing45:00 What red teams add47:00 Standards, certification, and assurance53:00 Looking toward the future54:00 Goals for the next generation of software56:00 Software minimalism and reducing attack surface59:00 Policy as a driver for change62:00 Closing thoughts
Embed this episode
What this episode covers
Software security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now. Drawing on work at Parasoft and across government and industry, Kevin discusses secure development practices, standards, developer enablement, and the limits of relying on tools alone. The conversation connects supply-chain failures and the federal cybersecurity executive order to cyber resilience, penetration te...
Ready to play
Thinking back, Looking forward - A Balanced Approach to Securing our Software Future
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.