
Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10
Om avsnittet
How should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use? Andrew van der Stock and Brian Glas discuss the governance and research behind the project’s next release during a contentious revision cycle. They explain how public comments affect decisions, why a large share of contributed data came from one source, and how the team planned to compare findings across applications. The conversation covers scoring, release candidates, the familiar one-page format, and connections to ASVS, Proactive Controls, and the Web Security Testing Guide. Chris presses them on what the list should become in the future and how listeners can participate. The result is a candid view of maintaining a widely influential community standard.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Andrew van der Stock and Brian Glas:
→ Andrew van der Stock on LinkedIn
→ Brian Glas on LinkedIn
→ OWASP Top 10
Mentioned in this episode:
→ OWASP Top 10
→ OWASP ASVS
→ OWASP Proactive Controls
→ OWASP Web Security Testing Guide
→ OWASP ESAPI
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The future of the OWASP Top 10
02:21 Andrew van der Stock’s security origin story
05:30 Experience maintaining the project
06:36 Governance and decision-making
08:13 How public comments affect the release
10:57 Data concentration in the first candidate
13:15 Comparing findings across applications
16:07 Scoring and understanding impact
19:30 The origins of ASVS
21:22 Connecting the Top 10 to other OWASP projects
23:06 The release-candidate schedule
26:21 Preserving the one-page format
28:58 What the Top 10 should become
33:16 How listeners can participate
34:26 Final thoughts
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.