Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Chris Romeo -- Security Culture Hacking: Disrupting the Security Status Quo

32 min10 december 2018

Om avsnittet

Changing security culture requires more than distributing policies or buying another training platform. In this recorded AppSec USA presentation, Chris Romeo shares practical ways to influence how an organization thinks and acts about software security. He explains why every organization already has a security culture, how to assess it, and why the assessment must lead to action. The talk explores speaking the language of developers and executives, sharing information openly, building a champions community, and recognizing useful behavior. Chris also describes learning experiences that fit developers’ work and demonstrations that make application risk concrete for leaders. He closes by connecting culture change to observable outcomes, including whether teams resolve security problems more quickly over time.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Chris Romeo:
Chris Romeo on LinkedIn

Mentioned in this episode:
OWASP SAMM
OWASP Juice Shop
WebGoat
DevSlop

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Security culture hacking at AppSec USA
08:05 Every organization already has a security culture
09:53 Transparency and sharing security knowledge
10:07 Assessing and measuring the starting point
11:39 Turning assessment into an action strategy
12:34 Learning developers’ language and methods
13:49 Speaking to executives about risk and value
14:24 Communication and security’s own assumptions
17:37 Building a deliberate security community
18:06 Champions programs and learning sessions
19:57 Recognition and incentives for useful behavior
22:45 Developer-friendly learning and hands-on practice
27:43 Educating executives about application security
29:04 Demonstrating risk and measuring improvement

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.