
Chris and Robert -- #AppSec Recommendations
Om avsnittet
Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers. Their list moves from foundational software design and architecture books to secure development, threat modeling, web security, DevOps, checklists, blogs, recorded talks, and local conferences. They discuss learning from Irongeek and YouTube, following practitioners such as Troy Hunt, and using gatherings like BSides, SOURCE, and Black Hat to build relationships as well as technical knowledge. The episode is not a ranked shopping list; it is a guide to assembling a balanced learning practice from books, current writing, hands-on material, video, and community participation.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo and Robert Hurlbut:
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ Agile Application Security: Enabling Security in a Continuous Delivery Pipeline
→ Iron Geek
→ The DevOps Handbook
→ Threat Modeling: Designing for Security
→ The Tangled Web: A Guide to Securing Modern Web Applications
→ Start with Why: How Great Leaders Inspire Everyone to Take Action
→ Books by Martin Fowler
→ Troy Hunt
→ Have I Been Pwned
→ Google Alerts
→ The Checklist Manifesto: How to Get Things Right
→ BSides
→ Black Hat
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Chris and Robert’s AppSec recommendations
01:25 Building a balanced learning list
02:47 Foundational design and architecture books
04:36 Secure development books
06:03 Core software security
07:35 Irongeek, YouTube, and recorded talks
09:25 Threat modeling books
12:07 Security blogs and current writing
13:58 AppSec conferences
15:19 SOURCE, BSides, and Black Hat
16:44 Why local conferences matter
19:45 Web application security references
21:40 Learning from practitioners
24:49 The Checklist Manifesto
27:01 Community and final recommendations
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.