Tommy Ross — The BSA Framework for Secure Software episode artwork

EPISODE · Jul 19, 2019 · 36 MIN

Tommy Ross — The BSA Framework for Secure Software

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Software producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product. Tommy Ross, a policy leader at BSA and a drafter of its Framework for Secure Software, explains how the framework was created and who it is meant to help. He describes its outcome-focused structure, the relationship between functions and more specific categories, and the role of existing industry practices. The conversation uses software supply-chain requirements to show how a high-level goal can become a useful discussion about evidence and risk. Tommy also explores procurement questions, policy needs, and the process for collecting feedback. The result is an introduction to a shared vocabulary for evaluating software security.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tommy Ross:→ Tommy Ross at RSA ConferenceMentioned in this episode:→ BSA Framework for Secure Software — PDF→ Framework repository→ SAFECodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The BSA Framework for Secure Software01:24 Tommy’s path into security policy04:17 What BSA does06:09 Introducing the software security framework10:27 Producers, buyers, and policymakers as audiences14:24 A common vocabulary for customer requirements20:10 How the framework was developed24:05 Functions, categories, and outcomes27:21 A software supply-chain example28:17 Applying a requirement in practice29:20 Questions policymakers can ask32:51 Finding the document and contributing feedback

Episode metadata supplied by the publisher feed · Published Jul 19, 2019

Embed this episode

Software producers, customers, and policymakers need a common way to discuss security without pretending that one checklist fits every product. Tommy Ross, a policy leader at BSA and a drafter of its Framework for Secure Software, explains how the framework was created and who it is meant to help. He describes its outcome-focused structure, the relationship between functions and more specific categories, and the role of existing industry practices. The conversation uses software supply-chain ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Tommy Ross — The BSA Framework for Secure Software

0:00 36:58

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 19, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!