Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris and Robert -- #AppSec Recommendations

29 min9 mars 2018

Om avsnittet

Which books, sites, conferences, and communities are genuinely useful for learning application security? Chris and Robert compare their personal recommendations and explain what each resource offers. Their list moves from foundational software design and architecture books to secure development, threat modeling, web security, DevOps, checklists, blogs, recorded talks, and local conferences. They discuss learning from Irongeek and YouTube, following practitioners such as Troy Hunt, and using gatherings like BSides, SOURCE, and Black Hat to build relationships as well as technical knowledge. The episode is not a ranked shopping list; it is a guide to assembling a balanced learning practice from books, current writing, hands-on material, video, and community participation.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo and Robert Hurlbut:
Chris Romeo on LinkedIn
Robert Hurlbut on LinkedIn

Mentioned in this episode:
Agile Application Security: Enabling Security in a Continuous Delivery Pipeline
Iron Geek
The DevOps Handbook
Threat Modeling: Designing for Security
The Tangled Web: A Guide to Securing Modern Web Applications
Start with Why: How Great Leaders Inspire Everyone to Take Action
Books by Martin Fowler
Troy Hunt
Have I Been Pwned
Google Alerts
The Checklist Manifesto: How to Get Things Right
BSides
Black Hat

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Chris and Robert’s AppSec recommendations
01:25 Building a balanced learning list
02:47 Foundational design and architecture books
04:36 Secure development books
06:03 Core software security
07:35 Irongeek, YouTube, and recorded talks
09:25 Threat modeling books
12:07 Security blogs and current writing
13:58 AppSec conferences
15:19 SOURCE, BSides, and Black Hat
16:44 Why local conferences matter
19:45 Web application security references
21:40 Learning from practitioners
24:49 The Checklist Manifesto
27:01 Community and final recommendations

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.