
Andrew Van Der Stock -- The New OWASP Top Ten
Om avsnittet
Andrew Van Der Stok, a leading web application security specialist and executive director at OWASP joins us for this episode. We discuss the latest with the OWASP Top 10 Project, the importance of data collection, and the need for developer engagement. Andrew gives us the methodology behind building the OWASP Top 10, the significance of framework security, and much more. Andrew Vanderstock is a seasoned web application security specialist and enterprise security architect. He's the executive director at OWASP, taking the foundation through organizational change and taking OWASP's mission to the next level. Andrew has worked in the IT industry for over 25 years, has researched and developed the web application security and architecture fields since 1998.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization.
→ Learn more about Security Journey
Connect with Andrew van der Stock:
→ The Crown Road by Iain Banks
→ Edward Tufte
Mentioned in this episode:
→ The Crown Road by Iain Banks
→ Edward Tufte
→ OWASP Top Ten Project
→ OWASP Developer Guide
→ PCI DSS
→ OWASP Top Ten for LLM Applications project homepage
→ RSA Conference
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Andrew van der Stock: The New OWASP Top Ten
01:41 We are about to go on a journey into the topic
04:10 Phone goes with you probably just for emergency purposes, but so
07:27 Probably get ways to deal with it, right
13:08 Help me, help me remember what, what, what is the connection
15:29 On the topic of OWASP Top 10, give us an update
17:16 We talk about data and the need for data, I don't
20:58 Then if— so the, the request for data is really more
21:56 Now I'm curious. I want to dig a little deeper on
26:00 Are the downsides of, potential downsides of this data collection approach
30:23 That data weighted different in the model if it comes from
33:33 Wrapping all of this kind of together, we've got the data
35:14 I mean, or it used to be. Yeah. Or it used
36:24 I can, I mean, just to second something you said a
40:38 Yeah. So you already jumped ahead to controversial opinion, but before
42:23 All right. Yes, we already talked about the controversial opinions. So
45:59 Great. Last question is, what's your top book recommendation and why
50:12 Andrew, what's, how about a key takeaway then
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.