
Conclusion: All the Pieces You Need for an #AppSec Program
Om avsnittet
Which practices belong in a complete application security program? The Season 3 finale answers by assembling clips that move from early development decisions through testing, resilience, and runtime detection. Kevin Greene explains shifting left, Robert Hurlbut defines security champions, Pete Chestna distinguishes SAST, DAST, IAST, and RASP, and Megan Wu describes burnout and its warning signs. Jim Manico presents the OWASP Cheat Sheet Series, David Habusha explains software composition analysis and the Equifax example, and John Melton closes with OWASP AppSensor. Chris and Robert use the clips to show that AppSec is not one tool or one team; it is a connected set of technical practices, community roles, and sustainable working habits.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Chris Romeo and Robert Hurlbut:
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ OWASP Cheat Sheet Series
→ OWASP AppSensor
→ OWASP Dependency-Check
→ National Vulnerability Database
→ OWASP Cheat Sheet Series
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Building a complete AppSec program
00:50 Kevin Greene on shifting left
04:58 Robert Hurlbut on security champions
06:38 Pete Chestna on SAST, DAST, IAST, and RASP
10:16 Megan Wu on recognizing burnout
12:50 Jim Manico on the OWASP Cheat Sheet Series
17:35 David Habusha on software composition analysis
20:45 Could SCA have prevented Equifax?
22:44 John Melton on OWASP AppSensor
28:05 Closing Season 3
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.