EPISODE · Jul 19, 2019 · 36 MIN
Tommy Ross — The BSA Framework for Secure Software
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Software producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product. Tommy Ross, a policy leader at BSA and a drafter of its Framework for Secure Software, explains how the framework was created and who it is meant to help. He describes its outcome-focused structure, the relationship between functions and more specific categories, and the role of existing industry practices. The conversation uses software supply-chain requirements to show how a high-level goal can become a useful discussion about evidence and risk. Tommy also explores procurement questions, policy needs, and the process for collecting feedback. The result is an introduction to a shared vocabulary for evaluating software security.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tommy Ross:→ Tommy Ross at RSA ConferenceMentioned in this episode:→ BSA Framework for Secure Software — PDF→ Framework repository→ SAFECodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The BSA Framework for Secure Software01:24 Tommy’s path into security policy04:17 What BSA does06:09 Introducing the software security framework10:27 Producers, buyers, and policymakers as audiences14:24 A common vocabulary for customer requirements20:10 How the framework was developed24:05 Functions, categories, and outcomes27:21 A software supply-chain example28:17 Applying a requirement in practice29:20 Questions policymakers can ask32:51 Finding the document and contributing feedback
Embed this episode
What this episode covers
Software producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product. Tommy Ross, a policy leader at BSA and a drafter of its Framework for Secure Software, explains how the framework was created and who it is meant to help. He describes its outcome-focused structure, the relationship between functions and more specific categories, and the role of existing industry practices. The conversation uses software supply-chain ...
Ready to play
Tommy Ross — The BSA Framework for Secure Software
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.