
Chris and Robert -- The Activities of the Secure Development Lifecycle
Om avsnittet
Which activities turn a secure development lifecycle from an aspiration into repeatable work? Chris and Robert walk through security requirements, authentication and authorization, threat modeling, coding standards, approved libraries, code review, static analysis, dependency management, dynamic scanning, penetration testing, and post-release response. For each activity, they explain who benefits, when it belongs in development, and what it can reveal that another control cannot. The conversation emphasizes shared ownership: architects, developers, testers, operations, and response teams each see different parts of the risk. Tools support the process but do not replace design judgment or human testing. The episode provides a practical map of the SDL and shows how its activities connect from initial requirements through production feedback.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo and Robert Hurlbut:
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ OWASP Top 10
→ OWASP ESAPI
→ Microsoft Safe C Library
→ PSIRT Services Framework (FIRST.org)
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Activities of a secure development lifecycle
01:45 Security requirements
03:27 Authentication and authorization
05:24 Capturing requirements in development work
07:17 Threat modeling
09:12 Identifying threats systematically
12:14 How threat models help testers
14:09 Secure coding standards
15:52 Why developers need actionable guidance
17:44 Approved frameworks and cryptography
20:49 Code review and static analysis
23:53 Owning third-party dependency risk
25:18 Software composition analysis
26:53 Triage and false positives
29:38 Testing within the delivery process
31:26 Dynamic application security testing
33:07 Network versus application scanning
35:23 Comparing multiple tools
37:35 Why penetration testing still matters
40:45 Product security incident response
43:37 Secure software as a connected system
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.