Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Andrew van der Stock and Brian Glas -- The Future of the OWASP Top 10

36 min25 september 2017

Om avsnittet

How should the OWASP Top 10 balance data, expert judgment, community feedback, and a format people can actually use? Andrew van der Stock and Brian Glas discuss the governance and research behind the project’s next release during a contentious revision cycle. They explain how public comments affect decisions, why a large share of contributed data came from one source, and how the team planned to compare findings across applications. The conversation covers scoring, release candidates, the familiar one-page format, and connections to ASVS, Proactive Controls, and the Web Security Testing Guide. Chris presses them on what the list should become in the future and how listeners can participate. The result is a candid view of maintaining a widely influential community standard.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Andrew van der Stock and Brian Glas:
Andrew van der Stock on LinkedIn
Brian Glas on LinkedIn
OWASP Top 10

Mentioned in this episode:
OWASP Top 10
OWASP ASVS
OWASP Proactive Controls
OWASP Web Security Testing Guide
OWASP ESAPI

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 The future of the OWASP Top 10
02:21 Andrew van der Stock’s security origin story
05:30 Experience maintaining the project
06:36 Governance and decision-making
08:13 How public comments affect the release
10:57 Data concentration in the first candidate
13:15 Comparing findings across applications
16:07 Scoring and understanding impact
19:30 The origins of ASVS
21:22 Connecting the Top 10 to other OWASP projects
23:06 The release-candidate schedule
26:21 Preserving the one-page format
28:58 What the Top 10 should become
33:16 How listeners can participate
34:26 Final thoughts

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.